From 18f070dc10fadaa523880b40c815596b1779191e Mon Sep 17 00:00:00 2001 From: curben-bot <3048979-curben-bot@users.noreply.gitlab.com> Date: Sat, 3 Apr 2021 12:12:44 +0000 Subject: [PATCH] Filter updated: Sat, 03 Apr 2021 12:12:43 UTC --- urlhaus-filter-ag-online.txt | 426 +- urlhaus-filter-ag.txt | 149 +- urlhaus-filter-agh-online.txt | 355 +- urlhaus-filter-agh.txt | 87 +- urlhaus-filter-bind-online.conf | 73 +- urlhaus-filter-bind.conf | 37 +- urlhaus-filter-dnsmasq-online.conf | 73 +- urlhaus-filter-dnsmasq.conf | 37 +- urlhaus-filter-domains-online.txt | 355 +- urlhaus-filter-domains.txt | 87 +- urlhaus-filter-hosts-online.txt | 73 +- urlhaus-filter-hosts.txt | 37 +- urlhaus-filter-online.tpl | 73 +- urlhaus-filter-online.txt | 426 +- urlhaus-filter-rpz-online.conf | 75 +- urlhaus-filter-rpz.conf | 39 +- urlhaus-filter-snort2-online.rules | 8584 +++++++++++++------------- urlhaus-filter-snort3-online.rules | 8584 +++++++++++++------------- urlhaus-filter-suricata-online.rules | 8584 +++++++++++++------------- urlhaus-filter-unbound-online.conf | 73 +- urlhaus-filter-unbound.conf | 37 +- urlhaus-filter-vivaldi-online.txt | 426 +- urlhaus-filter-vivaldi.txt | 149 +- urlhaus-filter.tpl | 37 +- urlhaus-filter.txt | 149 +- 25 files changed, 14207 insertions(+), 14818 deletions(-) diff --git a/urlhaus-filter-ag-online.txt b/urlhaus-filter-ag-online.txt index 3ecd0d28..7f57ac6a 100644 --- a/urlhaus-filter-ag-online.txt +++ b/urlhaus-filter-ag-online.txt @@ -1,5 +1,5 @@ ! Title: Online Malicious URL Blocklist (AdGuard) -! Updated: Sat, 03 Apr 2021 00:13:46 UTC +! Updated: Sat, 03 Apr 2021 12:12:28 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -7,6 +7,7 @@ ||0-24bpautomentes.hu$all ||0cl.sldov.ru$all ||1.11.234.99$all +||1.186.151.219$all ||1.222.196.60$all ||1.245.4.163$all ||1.246.222.107$all @@ -16,11 +17,9 @@ ||1.246.222.134$all ||1.246.222.138$all ||1.246.222.14$all -||1.246.222.16$all ||1.246.222.165$all ||1.246.222.20$all ||1.246.222.228$all -||1.246.222.232$all ||1.246.222.234$all ||1.246.222.237$all ||1.246.222.245$all @@ -41,6 +40,7 @@ ||1.246.223.103$all ||1.246.223.105$all ||1.246.223.109$all +||1.246.223.126$all ||1.246.223.127$all ||1.246.223.130$all ||1.246.223.146$all @@ -78,12 +78,10 @@ ||101.73.131.78$all ||101.75.157.99$all ||101.75.167.213$all -||101.99.94.15$all ||102.130.115.14$all ||102.141.240.139$all ||103.113.99.79$all ||103.125.218.107$all -||103.136.82.50$all ||103.141.138.118$all ||103.141.138.12$all ||103.146.174.208$all @@ -92,12 +90,11 @@ ||103.217.215.21$all ||103.224.200.146$all ||103.224.200.40$all -||103.227.118.129$all +||103.237.21.36$all ||103.238.228.4$all ||103.240.249.121$all ||103.4.117.26$all ||103.70.160.51$all -||103.79.112.254$all ||103.82.98.170$all ||103.84.240.130$all ||103.91.245.12$all @@ -142,6 +139,7 @@ ||109.124.90.229$all ||109.233.196.232$all ||109.235.7.228$all +||109.248.58.238$all ||109.86.85.253$all ||109.95.200.102$all ||109.95.200.230$all @@ -155,28 +153,27 @@ ||110.228.195.46$all ||110.241.119.168$all ||110.248.124.254$all +||110.248.175.141$all ||110.248.251.194$all ||110.251.10.18$all ||110.253.150.248$all ||110.253.213.198$all +||110.253.51.112$all ||110.255.101.184$all ||110.255.167.147$all ||110.35.145.127$all ||110.35.208.21$all -||110.35.221.77$all ||110.35.223.92$all ||110.35.225.24$all -||110.35.233.147$all ||110.35.235.57$all +||110.35.249.21$all ||110.35.4.2$all ||110fss.net$all -||111.118.111.207$all ||111.118.41.173$all ||111.118.88.61$all ||111.119.245.114$all ||111.125.67.125$all ||111.165.21.195$all -||111.165.248.134$all ||111.166.236.191$all ||111.167.151.156$all ||111.170.85.71$all @@ -193,22 +190,20 @@ ||111.38.103.66$all ||111.38.104.141$all ||111.38.104.15$all -||111.38.106.128$all ||111.38.106.19$all ||111.38.121.222$all ||111.38.121.223$all ||111.38.121.226$all ||111.38.121.228$all ||111.38.26.243$all +||111.38.8.81$all ||111.61.52.53$all ||112.111.108.184$all -||112.111.31.175$all ||112.133.222.151$all ||112.147.92.51$all ||112.159.108.96$all ||112.163.200.217$all ||112.170.124.75$all -||112.170.233.9$all ||112.186.210.211$all ||112.186.96.252$all ||112.187.91.117$all @@ -262,18 +257,15 @@ ||112.247.81.173$all ||112.247.82.122$all ||112.248.148.90$all -||112.248.179.239$all ||112.248.197.164$all ||112.249.109.217$all ||112.249.118.157$all ||112.249.26.129$all ||112.249.79.98$all ||112.250.102.173$all -||112.250.57.99$all ||112.251.218.210$all ||112.252.136.84$all ||112.252.196.17$all -||112.252.212.122$all ||112.252.221.244$all ||112.252.239.103$all ||112.254.208.123$all @@ -309,7 +301,6 @@ ||112.27.124.177$all ||112.27.124.178$all ||112.27.124.179$all -||112.27.124.71$all ||112.27.127.155$all ||112.27.83.182$all ||112.27.83.23$all @@ -334,7 +325,6 @@ ||112.30.1.91$all ||112.30.110.31$all ||112.30.110.36$all -||112.30.110.37$all ||112.30.110.38$all ||112.30.110.41$all ||112.30.110.43$all @@ -349,21 +339,23 @@ ||112.30.4.136$all ||112.30.4.52$all ||112.31.240.239$all -||112.31.82.160$all ||112.31.87.98$all ||112.53.224.79$all ||112.65.53.175$all +||112.72.153.37$all +||112.72.162.159$all ||112.72.162.49$all ||112.72.162.53$all ||112.72.176.112$all ||112.72.176.84$all -||112.72.231.35$all +||112.72.226.202$all ||112.78.45.158$all ||112.80.117.32$all ||112.80.118.16$all ||112.80.127.91$all ||112.80.207.144$all ||112.80.215.101$all +||112.80.218.56$all ||112.82.146.253$all ||112.82.18.255$all ||112.82.224.139$all @@ -381,16 +373,14 @@ ||113.231.211.131$all ||113.254.169.251$all ||113.59.128.133$all -||113.59.136.39$all +||113.59.133.16$all ||113.59.154.21$all ||113.59.191.47$all ||113.61.204.205$all -||113.87.174.63$all -||113.87.175.135$all -||113.89.42.50$all ||113.89.43.185$all ||113.90.26.136$all -||114.199.204.37$all +||114.111.242.3$all +||114.199.253.235$all ||114.200.154.181$all ||114.224.203.128$all ||114.226.100.56$all @@ -398,31 +388,24 @@ ||114.229.165.194$all ||114.235.115.236$all ||114.30.54.64$all -||114.32.237.100$all ||114.79.172.42$all ||115.165.216.112$all ||115.201.38.185$all ||115.42.47.36$all -||115.48.204.56$all ||115.50.21.56$all ||115.51.125.55$all ||115.52.18.65$all -||115.55.144.42$all -||115.55.145.147$all ||115.55.153.194$all -||115.55.190.144$all ||115.55.60.129$all ||115.56.131.242$all ||115.56.133.96$all ||115.56.144.213$all ||115.56.159.132$all -||115.56.187.173$all ||115.58.132.140$all ||115.58.165.147$all -||115.59.240.217$all ||115.59.255.194$all ||115.61.118.201$all -||115.62.26.39$all +||115.69.102.84$all ||115.73.3.11$all ||115.92.174.231$all ||116.124.219.2$all @@ -431,15 +414,21 @@ ||116.211.100.26$all ||116.212.132.119$all ||116.212.142.215$all -||117.196.49.249$all +||117.194.166.219$all ||117.196.50.107$all ||117.20.204.138$all ||117.20.204.5$all ||117.20.210.52$all +||117.20.220.126$all ||117.20.236.14$all ||117.20.243.40$all +||117.20.247.150$all ||117.200.76.54$all -||117.26.110.103$all +||117.202.66.15$all +||117.202.69.113$all +||117.213.10.108$all +||117.213.15.72$all +||117.248.63.12$all ||117.63.113.146$all ||117.63.195.140$all ||117.63.53.15$all @@ -464,12 +453,11 @@ ||118.42.125.246$all ||118.43.180.33$all ||118.79.125.92$all -||118.79.218.157$all ||118.79.50.203$all ||118.79.58.82$all -||118.79.96.11$all ||118.83.79.43$all ||118.91.24.27$all +||118.91.41.135$all ||118.99.179.164$all ||118.99.183.235$all ||118.99.239.217$all @@ -480,7 +468,6 @@ ||119.147.213.57$all ||119.163.93.191$all ||119.164.18.235$all -||119.164.218.229$all ||119.165.107.93$all ||119.165.163.220$all ||119.165.174.63$all @@ -493,8 +480,6 @@ ||119.167.26.33$all ||119.177.147.38$all ||119.178.248.123$all -||119.179.157.219$all -||119.179.16.149$all ||119.179.170.212$all ||119.179.43.1$all ||119.179.75.8$all @@ -503,7 +488,6 @@ ||119.180.108.227$all ||119.180.108.79$all ||119.180.33.161$all -||119.180.94.80$all ||119.181.119.21$all ||119.181.124.203$all ||119.182.97.232$all @@ -523,12 +507,12 @@ ||119.251.105.221$all ||119.251.14.251$all ||119.56.131.155$all +||119.56.140.73$all ||119.56.143.46$all ||119.56.143.71$all ||119.56.144.75$all ||119.56.148.115$all ||119.56.155.57$all -||119.56.172.28$all ||119.56.175.41$all ||119.56.195.90$all ||119.56.206.43$all @@ -559,22 +543,17 @@ ||120.193.91.212$all ||120.193.91.215$all ||120.193.91.233$all -||120.209.121.243$all ||120.209.126.206$all ||120.209.126.240$all ||120.209.127.187$all ||120.209.99.127$all ||120.210.89.79$all ||120.43.33.202$all -||120.5.15.95$all ||120.50.66.60$all ||120.50.93.115$all -||120.6.141.142$all ||120.6.8.11$all ||120.7.75.99$all ||120.85.173.168$all -||120.85.174.3$all -||120.85.210.232$all ||121.100.114.164$all ||121.100.96.8$all ||121.121.44.222$all @@ -595,10 +574,8 @@ ||121.237.226.202$all ||121.239.15.74$all ||121.24.116.173$all -||121.25.101.86$all ||121.254.43.215$all ||121.254.76.17$all -||121.61.101.125$all ||121.61.98.151$all ||121.88.99.236$all ||122.100.150.204$all @@ -609,7 +586,6 @@ ||122.199.66.28$all ||122.199.72.23$all ||122.199.79.27$all -||122.199.83.86$all ||122.202.37.85$all ||122.202.41.23$all ||122.254.29.37$all @@ -626,28 +602,26 @@ ||123.128.133.91$all ||123.129.84.36$all ||123.130.208.52$all -||123.130.23.110$all ||123.130.27.19$all ||123.130.37.182$all -||123.130.61.210$all -||123.130.77.225$all ||123.131.186.250$all ||123.132.219.147$all ||123.133.125.77$all ||123.133.98.135$all ||123.134.14.130$all ||123.134.50.186$all -||123.14.120.130$all ||123.14.199.130$all +||123.14.248.210$all ||123.153.80.178$all ||123.154.116.116$all ||123.154.236.114$all ||123.154.94.1$all ||123.156.136.21$all +||123.159.68.119$all ||123.159.8.100$all ||123.183.121.60$all -||123.191.150.147$all ||123.191.164.92$all +||123.191.62.239$all ||123.192.101.163$all ||123.192.194.233$all ||123.193.149.235$all @@ -672,13 +646,10 @@ ||123.241.148.58$all ||123.241.184.124$all ||123.28.217.23$all -||123.5.189.116$all ||123.5.5.242$all -||123.8.184.82$all ||124.119.108.87$all ||124.129.221.150$all ||124.129.76.230$all -||124.130.110.167$all ||124.130.40.31$all ||124.131.104.82$all ||124.131.151.135$all @@ -691,7 +662,6 @@ ||124.153.136.175$all ||124.153.236.6$all ||124.160.126.238$all -||124.163.163.193$all ||124.163.65.64$all ||124.163.72.102$all ||124.165.123.7$all @@ -715,8 +685,6 @@ ||125.40.75.22$all ||125.41.215.9$all ||125.43.53.9$all -||125.45.63.67$all -||125.46.129.159$all ||125.79.200.104$all ||128.116.133.92$all ||130.255.159.133$all @@ -728,10 +696,12 @@ ||139.216.102.151$all ||139.227.46.137$all ||14.102.17.222$all +||14.102.97.204$all ||14.136.80.242$all ||14.138.8.51$all -||14.178.163.235$all +||14.160.34.50$all ||14.189.247.118$all +||14.241.227.216$all ||14.37.222.190$all ||14.45.127.110$all ||14.46.25.17$all @@ -758,23 +728,19 @@ ||153.101.47.145$all ||153.3.152.106$all ||153.34.135.92$all -||153.36.126.35$all ||155.138.134.44$all ||158.101.165.14$all ||158.174.213.128$all -||158.247.195.165$all ||158.51.125.115$all ||159.224.74.112$all ||162.194.28.60$all ||162.209.98.174$all ||163.53.206.228$all ||165.90.16.5$all -||168.205.223.254$all ||170.81.238.178$all ||171.113.36.216$all ||171.113.38.107$all ||171.121.255.10$all -||171.34.112.42$all ||171.34.114.181$all ||171.34.176.217$all ||171.34.179.178$all @@ -784,6 +750,7 @@ ||172.114.244.127$all ||172.245.5.185$all ||172.245.5.190$all +||172.245.79.106$all ||172.245.81.19$all ||172.93.194.114$all ||173.167.85.89$all @@ -810,7 +777,6 @@ ||175.169.13.182$all ||175.201.104.192$all ||175.208.230.8$all -||175.212.6.169$all ||175.42.46.118$all ||175.9.24.110$all ||175.9.90.89$all @@ -822,7 +788,6 @@ ||176.111.174.67$all ||176.113.161.104$all ||176.113.161.113$all -||176.113.161.138$all ||176.113.161.60$all ||176.113.161.65$all ||176.113.161.66$all @@ -836,7 +801,7 @@ ||176.123.7.127$all ||176.123.9.243$all ||176.124.7.225$all -||176.221.242.166$all +||176.221.188.251$all ||176.240.84.106$all ||177.11.92.78$all ||177.131.226.235$all @@ -846,35 +811,31 @@ ||178.124.182.187$all ||178.141.142.15$all ||178.150.174.65$all +||178.151.143.2$all ||178.165.122.141$all ||178.175.0.200$all ||178.175.1.137$all -||178.175.1.153$all ||178.175.1.179$all ||178.175.1.248$all ||178.175.1.249$all ||178.175.1.250$all ||178.175.1.44$all ||178.175.1.80$all +||178.175.100.151$all +||178.175.100.7$all ||178.175.101.110$all ||178.175.101.232$all -||178.175.102.133$all ||178.175.102.171$all ||178.175.102.67$all ||178.175.103.98$all -||178.175.104.145$all ||178.175.104.155$all ||178.175.104.69$all -||178.175.105.125$all ||178.175.105.95$all -||178.175.106.118$all ||178.175.106.193$all -||178.175.106.201$all ||178.175.107.0$all ||178.175.107.245$all ||178.175.107.83$all ||178.175.108.105$all -||178.175.108.149$all ||178.175.108.87$all ||178.175.109.129$all ||178.175.109.26$all @@ -886,23 +847,19 @@ ||178.175.111.206$all ||178.175.112.135$all ||178.175.112.139$all +||178.175.112.140$all ||178.175.112.147$all ||178.175.112.159$all ||178.175.112.46$all ||178.175.112.58$all -||178.175.113.27$all ||178.175.114.114$all -||178.175.114.63$all ||178.175.115.110$all ||178.175.115.209$all ||178.175.116.101$all ||178.175.116.138$all -||178.175.116.168$all -||178.175.116.90$all ||178.175.117.30$all ||178.175.118.112$all ||178.175.118.146$all -||178.175.118.210$all ||178.175.119.102$all ||178.175.119.114$all ||178.175.119.69$all @@ -923,18 +880,15 @@ ||178.175.123.248$all ||178.175.123.26$all ||178.175.123.30$all -||178.175.123.48$all ||178.175.123.91$all ||178.175.124.131$all ||178.175.124.155$all ||178.175.124.4$all -||178.175.124.79$all ||178.175.125.14$all ||178.175.125.160$all ||178.175.125.220$all ||178.175.125.88$all ||178.175.126.129$all -||178.175.126.153$all ||178.175.126.252$all ||178.175.126.46$all ||178.175.127.202$all @@ -944,7 +898,6 @@ ||178.175.13.254$all ||178.175.15.199$all ||178.175.15.215$all -||178.175.15.35$all ||178.175.16.108$all ||178.175.16.116$all ||178.175.16.251$all @@ -953,20 +906,17 @@ ||178.175.17.118$all ||178.175.17.61$all ||178.175.18.23$all +||178.175.18.37$all ||178.175.18.75$all ||178.175.19.163$all ||178.175.19.174$all ||178.175.19.91$all -||178.175.2.118$all -||178.175.2.123$all ||178.175.2.209$all ||178.175.2.5$all ||178.175.20.117$all ||178.175.20.70$all ||178.175.20.97$all ||178.175.21.149$all -||178.175.21.184$all -||178.175.21.238$all ||178.175.22.237$all ||178.175.23.144$all ||178.175.23.176$all @@ -978,7 +928,6 @@ ||178.175.25.56$all ||178.175.26.215$all ||178.175.27.114$all -||178.175.27.127$all ||178.175.27.171$all ||178.175.27.213$all ||178.175.27.32$all @@ -986,18 +935,17 @@ ||178.175.27.46$all ||178.175.28.239$all ||178.175.28.47$all -||178.175.29.2$all ||178.175.29.21$all ||178.175.3.172$all ||178.175.3.214$all ||178.175.30.133$all ||178.175.30.151$all ||178.175.30.213$all -||178.175.31.251$all ||178.175.31.73$all ||178.175.32.146$all ||178.175.32.220$all ||178.175.32.89$all +||178.175.33.162$all ||178.175.33.7$all ||178.175.34.217$all ||178.175.34.247$all @@ -1014,11 +962,12 @@ ||178.175.4.144$all ||178.175.4.72$all ||178.175.40.136$all -||178.175.40.166$all ||178.175.40.228$all ||178.175.42.101$all ||178.175.42.6$all ||178.175.43.121$all +||178.175.43.223$all +||178.175.43.229$all ||178.175.43.238$all ||178.175.43.244$all ||178.175.44.0$all @@ -1031,13 +980,11 @@ ||178.175.45.26$all ||178.175.46.129$all ||178.175.46.137$all -||178.175.46.243$all ||178.175.46.41$all ||178.175.46.42$all ||178.175.46.8$all ||178.175.47.143$all ||178.175.48.51$all -||178.175.49.12$all ||178.175.5.57$all ||178.175.50.10$all ||178.175.50.177$all @@ -1056,10 +1003,8 @@ ||178.175.56.82$all ||178.175.56.87$all ||178.175.57.134$all -||178.175.57.179$all ||178.175.58.183$all ||178.175.58.79$all -||178.175.59.131$all ||178.175.59.33$all ||178.175.6.115$all ||178.175.6.140$all @@ -1071,15 +1016,12 @@ ||178.175.60.209$all ||178.175.60.212$all ||178.175.60.221$all -||178.175.61.235$all -||178.175.62.232$all ||178.175.62.70$all ||178.175.62.81$all ||178.175.63.21$all ||178.175.64.156$all ||178.175.66.186$all ||178.175.66.192$all -||178.175.66.211$all ||178.175.68.116$all ||178.175.68.123$all ||178.175.68.209$all @@ -1088,60 +1030,51 @@ ||178.175.69.153$all ||178.175.69.67$all ||178.175.7.105$all -||178.175.7.107$all ||178.175.7.14$all -||178.175.7.21$all ||178.175.7.35$all ||178.175.7.60$all ||178.175.7.79$all -||178.175.70.212$all ||178.175.70.218$all +||178.175.71.179$all ||178.175.72.222$all ||178.175.72.65$all -||178.175.73.42$all ||178.175.75.181$all ||178.175.75.244$all -||178.175.77.248$all -||178.175.77.46$all ||178.175.77.47$all ||178.175.78.169$all ||178.175.78.2$all -||178.175.8.181$all +||178.175.78.242$all ||178.175.80.89$all -||178.175.81.176$all ||178.175.81.226$all -||178.175.81.235$all ||178.175.81.31$all ||178.175.83.2$all +||178.175.83.247$all ||178.175.84.215$all -||178.175.84.61$all ||178.175.85.23$all ||178.175.85.53$all ||178.175.86.59$all ||178.175.87.146$all ||178.175.87.42$all ||178.175.87.91$all -||178.175.88.166$all ||178.175.88.4$all +||178.175.89.121$all ||178.175.89.217$all ||178.175.89.6$all ||178.175.9.179$all ||178.175.9.198$all ||178.175.9.4$all -||178.175.90.81$all +||178.175.90.4$all ||178.175.92.1$all ||178.175.92.102$all ||178.175.92.92$all ||178.175.93.143$all -||178.175.94.182$all ||178.175.94.27$all ||178.175.94.32$all ||178.175.94.40$all ||178.175.94.61$all ||178.175.95.120$all -||178.175.96.218$all ||178.175.96.251$all -||178.175.97.14$all +||178.175.97.113$all ||178.175.98.83$all ||178.175.99.120$all ||178.175.99.130$all @@ -1154,7 +1087,6 @@ ||178.222.252.130$all ||178.34.183.30$all ||178.48.235.59$all -||178.72.91.172$all ||178.95.136.35$all ||179.159.58.134$all ||179.60.84.7$all @@ -1163,7 +1095,6 @@ ||180.116.203.220$all ||180.122.13.227$all ||180.123.208.250$all -||180.125.44.194$all ||180.157.66.204$all ||180.175.236.209$all ||180.176.105.41$all @@ -1199,30 +1130,20 @@ ||182.116.61.252$all ||182.116.99.150$all ||182.117.43.185$all -||182.117.43.82$all ||182.119.120.8$all ||182.119.164.128$all -||182.119.200.62$all ||182.119.202.130$all ||182.120.16.22$all ||182.120.16.46$all -||182.121.127.106$all -||182.123.205.157$all -||182.123.211.239$all -||182.124.138.54$all -||182.126.121.211$all +||182.121.26.37$all ||182.127.152.3$all ||182.160.98.250$all ||182.233.0.252$all ||182.235.252.31$all ||182.53.197.62$all -||183.105.104.83$all ||183.105.225.154$all ||183.109.169.45$all ||183.128.152.115$all -||183.144.9.97$all -||183.185.112.19$all -||183.83.18.203$all ||183.83.29.191$all ||183.92.207.147$all ||184.164.185.41$all @@ -1249,7 +1170,6 @@ ||185.68.230.207$all ||185.81.157.186$all ||185.82.217.185$all -||185.82.217.213$all ||185.82.219.160$all ||185.82.219.161$all ||185.82.219.219$all @@ -1268,7 +1188,6 @@ ||187.12.10.98$all ||187.188.124.229$all ||187.212.200.162$all -||187.85.244.145$all ||188.10.21.14$all ||188.10.231.246$all ||188.113.81.17$all @@ -1277,6 +1196,8 @@ ||188.143.220.152$all ||188.152.41.141$all ||188.169.178.50$all +||188.169.179.127$all +||188.169.199.59$all ||188.242.242.144$all ||188.81.100.83$all ||188.83.202.25$all @@ -1316,7 +1237,6 @@ ||192.227.185.106$all ||192.227.209.27$all ||192.227.220.55$all -||192.227.223.96$all ||192.227.228.67$all ||192.227.230.74$all ||192.3.152.166$all @@ -1350,7 +1270,6 @@ ||1am.co.nz$all ||2.229.89.119$all ||2.239.22.188$all -||2.249.161.188$all ||2.37.149.230$all ||2.37.203.65$all ||2.45.4.24$all @@ -1362,7 +1281,6 @@ ||2.indexsinas.me:811/86.exe$all ||2.indexsinas.me:811/c64.exe$all ||20.185.42.197$all -||200.104.150.167$all ||200.105.167.98$all ||200.111.189.70$all ||200.194.4.24$all @@ -1373,11 +1291,10 @@ ||201.184.163.170$all ||201.187.102.73$all ||201.200.254.86$all +||201.203.221.20$all ||201.203.27.37$all -||201.205.12.170$all ||202.107.233.41$all ||202.150.176.100$all -||202.166.217.54$all ||202.175.103.10$all ||202.29.95.12$all ||202.4.124.58$all @@ -1390,7 +1307,6 @@ ||203.229.21.56$all ||203.236.190.28$all ||203.238.86.202$all -||203.243.142.132$all ||203.70.166.107$all ||203.77.80.159$all ||203.80.119.166$all @@ -1400,7 +1316,6 @@ ||204.195.116.171$all ||205.185.115.74$all ||205.185.116.94$all -||205.185.123.217$all ||206.248.137.132$all ||206.47.41.166$all ||207.180.228.101$all @@ -1410,8 +1325,8 @@ ||209.141.39.50$all ||209.141.40.190$all ||209.141.40.31$all -||209.141.46.87$all ||210.124.149.19$all +||210.180.17.140$all ||210.216.152.122$all ||210.216.153.142$all ||210.57.234.93$all @@ -1422,7 +1337,6 @@ ||211.116.220.37$all ||211.187.132.204$all ||211.187.75.220$all -||211.200.160.239$all ||211.204.215.157$all ||211.210.66.179$all ||211.210.93.93$all @@ -1440,31 +1354,31 @@ ||212.46.197.114$all ||212.56.197.230$all ||212.8.251.211$all +||212.8.251.227$all ||213.123.206.197$all ||213.135.178.253$all ||213.14.173.117$all ||213.149.182.113$all ||213.149.190.193$all -||213.163.104.12$all ||213.163.104.99$all ||213.163.113.135$all ||213.163.113.20$all ||213.163.113.237$all ||213.163.113.6$all ||213.163.114.165$all +||213.163.114.191$all ||213.163.115.105$all ||213.163.115.11$all ||213.163.115.15$all ||213.163.115.30$all ||213.163.115.71$all -||213.163.116.192$all ||213.163.117.151$all +||213.163.118.10$all ||213.163.118.238$all ||213.163.118.65$all ||213.163.119.236$all -||213.163.126.175$all +||213.163.126.145$all ||213.163.126.7$all -||213.163.127.107$all ||213.163.127.46$all ||213.189.178.163$all ||213.240.218.15$all @@ -1479,32 +1393,26 @@ ||216.183.54.169$all ||216.36.12.98$all ||217.11.75.162$all +||217.127.133.214$all ||218.12.181.110$all ||218.2.40.34$all ||218.234.165.18$all ||218.238.246.3$all -||218.28.160.174$all ||218.35.207.119$all ||218.35.227.133$all ||218.35.68.35$all ||218.35.81.81$all ||218.56.93.129$all -||218.58.92.253$all ||218.59.116.203$all -||218.72.207.116$all ||218.79.103.159$all ||218.93.102.63$all ||218.93.102.75$all ||219.155.102.14$all -||219.155.11.207$all -||219.155.12.85$all -||219.155.26.190$all ||219.155.29.165$all ||219.156.186.18$all ||219.157.139.165$all ||219.157.150.91$all ||219.157.214.235$all -||219.157.50.106$all ||219.241.6.180$all ||219.68.1.148$all ||219.68.1.84$all @@ -1513,19 +1421,17 @@ ||219.68.245.63$all ||219.68.5.140$all ||219.69.71.186$all +||219.70.238.66$all ||219.80.217.209$all ||219.85.145.194$all ||21robo.com$all ||220.118.168.155$all ||220.126.237.74$all ||220.200.22.163$all -||220.247.91.17$all ||220.71.239.115$all -||220.90.159.188$all ||221.1.144.183$all ||221.124.78.15$all -||221.15.113.234$all -||221.157.191.178$all +||221.15.125.69$all ||221.160.136.213$all ||221.202.232.230$all ||221.214.130.147$all @@ -1547,16 +1453,15 @@ ||222.119.65.145$all ||222.132.125.138$all ||222.133.103.120$all -||222.135.67.115$all ||222.135.9.5$all ||222.137.148.192$all ||222.137.211.78$all ||222.138.17.132$all ||222.138.237.155$all ||222.140.17.245$all -||222.162.187.43$all ||222.179.215.189$all ||222.185.116.233$all +||222.186.20.19$all ||222.187.9.178$all ||222.211.72.66$all ||222.236.85.220$all @@ -1607,6 +1512,7 @@ ||27.105.106.201$all ||27.105.152.107$all ||27.116.84.57$all +||27.14.211.219$all ||27.14.81.201$all ||27.141.218.17$all ||27.147.29.52$all @@ -1650,8 +1556,6 @@ ||27.207.155.31$all ||27.207.170.203$all ||27.208.119.27$all -||27.208.152.10$all -||27.208.160.177$all ||27.208.164.18$all ||27.208.237.105$all ||27.208.247.130$all @@ -1661,13 +1565,13 @@ ||27.209.208.122$all ||27.209.231.15$all ||27.210.107.125$all -||27.210.172.245$all ||27.210.234.28$all ||27.210.236.134$all +||27.210.32.122$all ||27.210.44.19$all ||27.210.63.243$all ||27.213.104.201$all -||27.213.109.58$all +||27.213.109.105$all ||27.213.175.208$all ||27.213.255.202$all ||27.213.66.112$all @@ -1677,9 +1581,9 @@ ||27.215.190.172$all ||27.215.212.209$all ||27.215.253.149$all -||27.215.34.242$all ||27.215.71.243$all ||27.215.98.242$all +||27.216.117.54$all ||27.216.128.156$all ||27.216.131.66$all ||27.216.144.66$all @@ -1701,17 +1605,13 @@ ||27.220.85.168$all ||27.221.239.223$all ||27.222.241.223$all -||27.222.249.210$all ||27.222.76.80$all ||27.223.242.164$all ||27.24.28.134$all ||27.35.129.198$all ||27.35.154.13$all -||27.35.16.145$all -||27.35.2.30$all ||27.35.212.124$all ||27.35.58.5$all -||27.41.237.129$all ||27.43.117.98$all ||31.0.98.131$all ||31.11.51.57$all @@ -1738,18 +1638,19 @@ ||32.208.157.193$all ||32792.prolocksmithwinterpark.com$all ||35.184.169.169$all -||36.107.209.10$all ||36.108.231.218$all ||36.248.228.64$all +||36.248.83.98$all ||36.250.203.246$all ||36.251.157.225$all ||36.251.18.18$all ||36.251.51.244$all ||36.255.90.219$all +||36.33.128.58$all ||36.33.160.167$all ||36.34.150.236$all ||36.66.105.159$all -||36.66.111.203$all +||36.66.133.125$all ||36.66.139.36$all ||36.89.18.133$all ||360.lcy2zzx.pw$all @@ -1819,7 +1720,6 @@ ||39.81.70.88$all ||39.83.94.11$all ||39.84.115.152$all -||39.85.54.191$all ||39.85.54.4$all ||39.86.129.233$all ||39.86.170.209$all @@ -1830,10 +1730,10 @@ ||39.88.155.96$all ||39.88.233.131$all ||39.88.67.238$all +||39.88.72.9$all ||39.89.108.109$all ||39.89.145.11$all ||39.89.146.198$all -||39.89.146.36$all ||39.89.63.23$all ||39.90.86.212$all ||40.88.2.151$all @@ -1844,14 +1744,15 @@ ||41.219.185.171$all ||41.226.60.115$all ||41.72.203.82$all -||41.86.18.169$all -||41.86.21.23$all +||41.86.18.133$all ||41.86.21.27$all -||41.86.21.38$all +||41.86.5.197$all ||42.202.101.199$all +||42.228.39.211$all ||42.228.43.161$all ||42.228.65.104$all ||42.230.82.176$all +||42.232.81.179$all ||42.235.180.147$all ||42.239.26.122$all ||42.56.15.227$all @@ -1865,7 +1766,9 @@ ||45.133.1.242$all ||45.133.203.192$all ||45.135.134.228$all +||45.14.149.182$all ||45.14.149.204$all +||45.141.84.182$all ||45.141.84.184$all ||45.144.225.118$all ||45.144.225.135$all @@ -1891,16 +1794,12 @@ ||45.51.104.59$all ||45.6.24.251$all ||45.81.235.31$all -||45.85.90.131$all -||45.85.90.179$all ||45.85.90.203$all ||45.9.148.37$all ||45.92.108.125$all -||45.95.169.153$all ||46.117.42.29$all ||46.172.75.231$all ||46.182.173.246$all -||46.182.173.247$all ||46.20.63.218$all ||46.214.27.4$all ||46.24.130.254$all @@ -1918,6 +1817,7 @@ ||47.16.131.51$all ||47.21.202.98$all ||47.46.231.38$all +||49.119.187.230$all ||49.142.162.113$all ||49.142.87.36$all ||49.143.43.93$all @@ -1932,7 +1832,6 @@ ||49.68.221.252$all ||5.188.62.111$all ||5.2.70.50$all -||5.42.37.74$all ||5.53.146.179$all ||5.79.75.210$all ||5.95.226.154$all @@ -1940,7 +1839,6 @@ ||50.115.174.106$all ||50.121.91.255$all ||50.252.47.29$all -||51.222.56.159$all ||54.36.114.136$all ||54.36.180.122$all ||58.114.246.26$all @@ -1955,16 +1853,15 @@ ||58.218.67.253$all ||58.22.212.107$all ||58.226.129.29$all -||58.229.194.122$all ||58.230.89.42$all ||58.238.42.192$all ||58.240.147.97$all ||58.241.78.55$all -||58.243.123.212$all ||58.243.126.133$all ||58.243.208.225$all -||58.248.118.64$all -||58.249.80.181$all +||58.248.142.227$all +||58.249.79.174$all +||58.249.84.131$all ||58.48.154.143$all ||58.72.165.153$all ||58.72.165.39$all @@ -1973,12 +1870,14 @@ ||59.0.211.161$all ||59.102.168.189$all ||59.151.202.3$all -||59.151.207.150$all ||59.151.214.4$all ||59.151.237.51$all ||59.151.246.125$all ||59.23.114.97$all ||59.58.117.226$all +||59.93.18.144$all +||59.96.37.124$all +||59.97.169.237$all ||60.10.91.242$all ||60.13.61.12$all ||60.164.130.220$all @@ -2003,9 +1902,7 @@ ||60.217.177.196$all ||60.217.86.208$all ||60.223.84.102$all -||60.25.109.240$all ||60.253.15.104$all -||60.253.39.88$all ||60.253.4.72$all ||60.253.51.127$all ||60.253.60.174$all @@ -2015,25 +1912,21 @@ ||60.7.8.43$all ||60.7.99.254$all ||61.164.96.98$all -||61.179.171.60$all ||61.179.91.194$all ||61.247.224.66$all ||61.253.94.230$all -||61.3.149.112$all ||61.41.230.161$all ||61.47.220.169$all ||61.52.103.217$all ||61.52.199.47$all -||61.52.207.10$all ||61.52.30.172$all ||61.52.9.166$all -||61.52.9.62$all ||61.52.99.161$all -||61.53.102.137$all ||61.53.117.237$all -||61.53.220.0$all +||61.53.89.220$all ||61.54.103.56$all ||61.54.64.63$all +||61.54.69.77$all ||61.56.180.67$all ||61.56.181.7$all ||61.57.96.116$all @@ -2134,7 +2027,6 @@ ||74.64.139.223$all ||74.75.165.81$all ||75.127.141.52$all -||75.82.36.220$all ||75.83.102.27$all ||75.99.213.61$all ||76.170.11.82$all @@ -2146,7 +2038,6 @@ ||76.95.12.137$all ||77.111.182.31$all ||77.237.25.210$all -||77.53.144.46$all ||77.71.50.153$all ||77.71.52.220$all ||77.89.203.238$all @@ -2168,6 +2059,7 @@ ||79.130.253.13$all ||79.147.123.48$all ||79.175.42.244$all +||79.21.84.63$all ||79.7.170.58$all ||79.79.58.94$all ||79.8.70.162$all @@ -2181,6 +2073,7 @@ ||81.165.44.109$all ||81.191.40.58$all ||81.213.141.184$all +||81.215.199.29$all ||81.218.187.113$all ||81.218.195.216$all ||81.237.128.200$all @@ -2248,7 +2141,7 @@ ||86.35.43.220$all ||87.172.19.130$all ||87.61.89.40$all -||87du.vip$all +||88.119.171.253$all ||88.2.208.71$all ||88.2.219.179$all ||88.225.222.128$all @@ -2282,6 +2175,7 @@ ||92.114.191.82$all ||92.241.78.114$all ||92.27.246.202$all +||92.54.237.237$all ||92.83.62.139$all ||92.85.18.138$all ||93.159.169.190$all @@ -2309,7 +2203,6 @@ ||95.60.146.134$all ||95.66.196.63$all ||95.9.120.40$all -||95.9.81.85$all ||96.239.73.246$all ||96.47.147.169$all ||97.68.140.254$all @@ -2383,6 +2276,7 @@ ||anantam.net.in$all ||andreelapeyre.com$all ||andremaraisbeleggings.co.za$all +||andreonemaia.com$all ||andres.ac.ug$all ||andres.ug$all ||andreshconcejal.solucioneslink.com$all @@ -2392,7 +2286,6 @@ ||anhung1102.vn$all ||anurontv.com$all ||anysbergbiltong.co.za$all -||apartamentoscitta.com$all ||api-ms.cobainaja.id$all ||api.cstdevs.com$all ||api.quocbao.biz$all @@ -2415,15 +2308,17 @@ ||attach.66rpg.com$all ||atteuqpotentialunlimited.com$all ||augustair.com$all +||aulist.com$all +||automaticrefreshments.com$all ||avadhanagames.com$all ||ayahuascasp.com.br$all ||ayamallah.com$all +||aycconsultoriaempresarial.com$all ||azmeasurement.com$all ||b2b.toptanakaryakit.com.tr$all ||backgrounds.pk$all ||badeggdesign.com$all ||balealgodon.mx$all -||ballina.andrewmaughan.com$all ||bangkok-orchids.com$all ||bangladeshunbound.com$all ||bary.sz4h.com$all @@ -2434,6 +2329,7 @@ ||bcmt.elin.co.za$all ||bcrg.co.za$all ||bdnextrend.xyz$all +||beanx88.xyz$all ||bearcatpumps.com.cn$all ||beautincollagen.rs$all ||bekape.co.id$all @@ -2441,6 +2337,7 @@ ||bespokeweddings.ie$all ||bestcarenepal.com$all ||betone.co.kr$all +||betycopaints.com$all ||beveragesmiami.solucioneslink.com$all ||bhavaniengineering.com$all ||bigmikesupplies.co.za$all @@ -2494,7 +2391,6 @@ ||bitbucket.org/tanake5518/fi/downloads/clientrevers.txt$all ||bitbucket.org/tanake5518/fi/downloads/dcrat.exe$all ||bitbucket.org/tanake5518/fi/downloads/dllservices.exe$all -||bitbucket.org/tanake5518/fi/downloads/dllservices2.exe$all ||bitbucket.org/tanake5518/fi/downloads/exe_morris.mcdermott.exe$all ||bitbucket.org/tanake5518/fi/downloads/hans.txt$all ||bitbucket.org/tanake5518/fi/downloads/hulu.txt$all @@ -2525,7 +2421,6 @@ ||bitbucket.org/tanake5518/fi/downloads/taurjok.txt$all ||bitbucket.org/tanake5518/fi/downloads/taurusbabac.exe$all ||bitbucket.org/tanake5518/fi/downloads/telekiller.exe$all -||bitbucket.org/tanake5518/fi/downloads/updateanddr.txt$all ||bitbucket.org/tanake5518/fi/downloads/updateandr.txt$all ||bitbucket.org/tanake5518/fi/downloads/vhajeja.txt$all ||bitbucket.org/tanake5518/fi/downloads/word.txt$all @@ -2549,6 +2444,7 @@ ||bounces.mi-fs.com$all ||boutiqueofferte.com$all ||bpo.correct.go.th$all +||bradleyinstitute.co.za$all ||brandtrust.com.pk$all ||braunfinancial.com.au$all ||brendanquine.com$all @@ -2608,6 +2504,7 @@ ||childselect.com$all ||chinhdropfile.myvnc.com$all ||chinhdropfile80.myvnc.com$all +||chipmania.it$all ||chiptune.com/razor/rzr-winner_intro.zip$all ||cible-energy.com$all ||cifeer.net$all @@ -2626,10 +2523,9 @@ ||codsambal.com$all ||colempaques.info$all ||colfincas.com/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/$all -||colinde.pricesne.com$all ||colorpak.pl$all +||columbia.aula-web.net$all ||community.reimclub.com$all -||comosairdoburaco.com.br$all ||competancy.indigoconsult.net$all ||conceptimagine.ro$all ||config.cqhbkjzx.com$all @@ -2645,7 +2541,6 @@ ||cpanel.shivay.net$all ||cr-sq.com$all ||craftech.nxtnet.ga$all -||crearechile.cl$all ||creationskateboards.com$all ||crecerco.com$all ||crittersbythebay.com$all @@ -2655,7 +2550,6 @@ ||crscorretordeimoveis.com.br$all ||cse-engineer.com$all ||csnserver.com$all -||ctracknxt.in$all ||cubescargoexpress.com$all ||curasoles.co.za$all ||currantmedia.com$all @@ -2674,7 +2568,6 @@ ||data.over-blog-kiwi.com$all ||datapolish.com$all ||dating.khokhas.co.za$all -||datsom.vn$all ||davethompson.me.uk$all ||davidmcguinness.info$all ||dayspringdaisies.com$all @@ -2699,7 +2592,6 @@ ||detorre.es$all ||dev.sebpo.net$all ||dev.watch-store.eu$all -||dezcom.com$all ||dfcf.91756.cn$all ||dfsfcsfcdsfsdvcfsvcscv.com$all ||diamantenegro.mi-fs.com$all @@ -2714,6 +2606,7 @@ ||dl.packetstormsecurity.net$all ||dl.rina-roleplay.com$all ||dnn.alibuf.com$all +||dns.alibuf.com$all ||dns.cyberium.cc$all ||dockerupdate.anondns.net$all ||docman.orientalservices.in$all @@ -2731,6 +2624,8 @@ ||dosman.pl$all ||dovberger.com$all ||down.pcclear.com$all +||down.postch-de.top$all +||down.postch-dl.top$all ||down.udashi.com$all ||down.webbora.com$all ||down1.arpun.com$all @@ -2761,7 +2656,6 @@ ||drive.google.com/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv$all ||drive.google.com/uc?export=download&id=1cos43rmscrescxk3u40qjuqbwr-pydsn$all ||drive.google.com/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben$all -||drive.google.com/uc?export=download&id=1dhoxtwbb2ycn8q06gi3p-ao_llldff0e$all ||drive.google.com/uc?export=download&id=1dnm3wtjf6ud5fv6zop9cvbr4rs2of1-n$all ||drive.google.com/uc?export=download&id=1dqin1sdd6rbah3sggzsxzeqgrkmhjnqm$all ||drive.google.com/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi$all @@ -2855,7 +2749,6 @@ ||f1sol.com$all ||fahrzeugdrive.com$all ||familydentist.site$all -||faveraprojects.com$all ||fc.co.mz$all ||felicienne.nl$all ||file.elecfans.com/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe$all @@ -2865,7 +2758,7 @@ ||filmotainment.com$all ||final.makkahkmcc.com$all ||fineartgallerym.com$all -||fisconline.casa$all +||fisconline.bar$all ||fix-america-now.org$all ||fixauto.illumetechnology.com$all ||fixturegovernment.com$all @@ -2880,7 +2773,6 @@ ||footweardirect.elin.co.za$all ||forum.mdb.nu$all ||fotoobjetivo.com$all -||foundationrepairhoustontx.net$all ||foxeps.com.br$all ||fraud.bpcbankingtech.com$all ||freecnetdownload.com$all @@ -2889,7 +2781,6 @@ ||fullelectronica.com.ar$all ||funletters.net$all ||fusionfiresolutions.com$all -||futbolpr.com$all ||futuregraphics.com.ar$all ||g.pinmonkey.xyz$all ||gametwogame.com$all @@ -2907,6 +2798,7 @@ ||giadungg7.com$all ||giddos.ga$all ||gist.githubusercontent.com/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe$all +||giteletropical.com$all ||glowinmedia.co.ke$all ||gmsebpl.com$all ||gmtransformationacademy.com$all @@ -2919,6 +2811,7 @@ ||goldcoastoffice365.com.au$all ||golden-memories-funerals.yourpageserver.com$all ||goldenasiacapital.com$all +||goldmen.in$all ||gorecycle.fahadjutt.com$all ||gpotecnosystems.com$all ||gracejukes.com$all @@ -2947,17 +2840,17 @@ ||highlandroadcoc.com$all ||highlandslasvegas.atakdev.com$all ||hindi.factsriver.com$all -||hiptool.net$all ||hitpe.com$all ||hitstation.nl$all +||hlmd.in$all ||hmpmall.co.kr$all ||hoagietesting10.com$all ||hoayeuthuong-my.sharepoint.com$all -||holmesservices.mobiledevsite.co$all ||homefindersolutions.com$all ||hongluosi.com$all ||hookedupboatclub.com$all ||hortizwp.eastus.cloudapp.azure.com$all +||hostingcloud.racing/7991.js$all ||hostingparacolombia.com$all ||hostzaa.com$all ||houstonshutters.site$all @@ -2966,7 +2859,6 @@ ||hrnautica.com.br$all ||hsecaravans.co.uk/wp-admin/suy/$all ||hseda.com$all -||hsmwebapp.com$all ||htownbars.com$all ||hubtech.co.za$all ||huellacero.cl$all @@ -3010,16 +2902,19 @@ ||ipmes.ma$all ||iremart.es$all ||iris101.co.uk$all +||isaac.mikhailmotoringschool.com$all ||iscamenabe.com$all ||isiphephelocon.co.za$all ||iso-dubai.net$all ||israrulhaq.me$all +||isrorg.com$all ||isso.ps$all ||ist-security.com$all ||it123.ru$all ||italiandirezione.casa$all ||itc-demo.softgig.co.ke$all ||itelsys.ma$all +||itmotasaciones.com$all ||jacktech.jackindia.com$all ||jaishritours.com$all ||jamiekaylive.com$all @@ -3034,6 +2929,7 @@ ||jhayesconsulting.com$all ||jiaoyuzixun.cn$all ||jing-da.com.tw$all +||jmtc.91756.cn$all ||jnanbharati.com$all ||jobs.thebeessolution.com$all ||joelbonissilver.com$all @@ -3047,6 +2943,7 @@ ||jupiter.toxsl.in$all ||justinscott.com.au$all ||kadigital.co.uk$all +||kaizenjanitorial.com$all ||kalawatihomes.com$all ||kalogirosfinance.com$all ||kaptaanchapal.com$all @@ -3113,14 +3010,16 @@ ||lp.definerisco.com$all ||lp.difusodesign.com$all ||lp.quama.pe$all -||ltc.typoten.com$all +||luckybrownie.com$all ||luminouspneuma.com$all ||luxomodels.com$all ||m-technics.kz$all ||m.estudiomoros.com.ar$all ||m.mobilelocalsales.com$all +||m.softsharks.com$all ||madicon.co.za$all ||magianegramagiablancayamarres.com$all +||maharaniworld.com$all ||mail.bs-eiendomme.co.za$all ||mail.golimoapp.com$all ||mail.jeffsono.org$all @@ -3133,6 +3032,7 @@ ||mangalyaa.lk$all ||manhtien.net$all ||marcapinyo.ru$all +||marcostrombetta.com.br/ds/1802.gif$all ||mario-sunjic.com$all ||mariobrown.net$all ||mariotessarollo.com$all @@ -3146,7 +3046,6 @@ ||maxiquim.cl$all ||maxoprint.co.uk$all ||maxtox.com.pk$all -||maybethescobar.com$all ||mbgrm.com$all ||mbjtimes.com$all ||mbsolutions.ge$all @@ -3177,12 +3076,13 @@ ||michimal2.000webhostapp.com$all ||microblading.mirliandias.com.br$all ||microcomm-group.com$all +||mikhailmotoringschool.com$all +||mills-skyla30ec.com$all ||mingguanwms.com$all ||minpic.de/k/big5/1giof6/$all ||minuevavida.org$all ||mirror.mypage.sk$all ||misterson.com$all -||mixr.at$all ||mkontakt.az$all ||mktf.mx$all ||mmdx.com$all @@ -3195,7 +3095,9 @@ ||moninediy.com$all ||mopai.sg$all ||moreirawag.ac.ug$all +||morrobaydrugandgift.com/wp-contentbak/t9m/$all ||motorcomunicacion.com$all +||moumitas.com/ds/0204.gif$all ||msacontabil.com.br$all ||mtspsmjeli.sch.id$all ||mumgee.co.za$all @@ -3222,6 +3124,7 @@ ||nec-i.com$all ||nedkellymyanmar.com$all ||nelitrianggraeni.000webhostapp.com$all +||nellaimasthanbiryani.com$all ||nerve.untergrund.net$all ||nettube.com.br$all ||networkwheels.co.za$all @@ -3248,7 +3151,6 @@ ||nobius.org$all ||nocalnoodle.elin.co.za$all ||nomadicbees.com$all -||nonnarina.ax$all ||notamuzikaletleri.com$all ||note.youdao.com/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a$all ||ns1.the-widyantos.com$all @@ -3270,6 +3172,7 @@ ||omega.az$all ||oms.pappai.com$all ||omscoc.pappai.com$all +||onedigitalcard.granvizionnecorp.com$all ||onedrive.listifyapp.co$all ||onedrive.live.com/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq$all ||onedrive.live.com/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq$all @@ -3295,8 +3198,6 @@ ||onedrive.live.com/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq$all ||onedrive.live.com/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko$all ||onedrive.live.com/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw$all -||onedrive.live.com/download?cid=032ce380af7ab389&resid=32ce380af7ab389!210&authkey=akcynbtc0h3ui7e$all -||onedrive.live.com/download?cid=032ce380af7ab389&resid=32ce380af7ab389%21210&authkey=akcynbtc0h3ui7e$all ||onedrive.live.com/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma$all ||onedrive.live.com/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48$all ||onedrive.live.com/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq$all @@ -3331,12 +3232,15 @@ ||onedrive.live.com/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4$all ||onedrive.live.com/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve$all ||onedrive.live.com/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w$all +||onedrive.live.com/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a$all ||onedrive.live.com/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a$all ||onedrive.live.com/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg$all ||onedrive.live.com/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60$all ||onedrive.live.com/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg$all ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4$all ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c$all +||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0$all +||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!140&authkey=apn44x6bxlzq3ac$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!151&authkey=aeuk7knodrpenek$all @@ -3346,30 +3250,20 @@ ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd$all -||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21140&authkey=apn44x6bxlzq3ac$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21151&authkey=aeuk7knodrpenek$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21153&authkey=ao6e8g0bzbp_idw$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21154&authkey=ah4chedbotzpmtq$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21156&authkey=ajnqscnmrdonpkg$all -||onedrive.live.com/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po$all ||onedrive.live.com/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe$all ||onedrive.live.com/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk$all ||onedrive.live.com/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca$all -||onedrive.live.com/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca$all ||onedrive.live.com/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu$all ||onedrive.live.com/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k$all ||onedrive.live.com/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo$all -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk$all -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei$all -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte$all -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk$all -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei$all -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte$all ||onedrive.live.com/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga$all ||onedrive.live.com/download?cid=2968c371f5450503&resid=2968c371f5450503!122&authkey=aaqhhxbnwfwrz28$all -||onedrive.live.com/download?cid=2968c371f5450503&resid=2968c371f5450503%21122&authkey=aaqhhxbnwfwrz28$all ||onedrive.live.com/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0$all ||onedrive.live.com/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620$all ||onedrive.live.com/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo$all @@ -3394,7 +3288,6 @@ ||onedrive.live.com/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8$all ||onedrive.live.com/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc$all ||onedrive.live.com/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0$all -||onedrive.live.com/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8$all ||onedrive.live.com/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus$all ||onedrive.live.com/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa$all ||onedrive.live.com/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa$all @@ -3413,7 +3306,6 @@ ||onedrive.live.com/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog$all ||onedrive.live.com/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog$all ||onedrive.live.com/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky$all -||onedrive.live.com/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky$all ||onedrive.live.com/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba!2203&authkey=ajvalmr5l8epwvm$all ||onedrive.live.com/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba%212203&authkey=ajvalmr5l8epwvm$all ||onedrive.live.com/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm$all @@ -3439,7 +3331,6 @@ ||onedrive.live.com/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc$all ||onedrive.live.com/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8$all -||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts$all @@ -3449,9 +3340,11 @@ ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas$all +||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i$all +||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy$all @@ -3478,9 +3371,11 @@ ||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so$all ||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq$all ||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s$all +||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww$all ||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8$all ||onedrive.live.com/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4$all ||onedrive.live.com/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu$all +||onedrive.live.com/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi$all ||onedrive.live.com/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8$all ||onedrive.live.com/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8$all ||onedrive.live.com/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2$all @@ -3489,6 +3384,7 @@ ||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8$all ||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq$all ||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8$all +||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq$all ||onedrive.live.com/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g$all ||onedrive.live.com/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum$all ||onedrive.live.com/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi$all @@ -3503,11 +3399,11 @@ ||onedrive.live.com/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki$all ||onedrive.live.com/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s$all ||onedrive.live.com/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki$all -||onedrive.live.com/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s$all ||onedrive.live.com/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc$all ||onedrive.live.com/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc$all ||onedrive.live.com/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo$all ||onedrive.live.com/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva$all +||onedrive.live.com/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc$all ||onedrive.live.com/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles$all ||onedrive.live.com/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg$all ||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai$all @@ -3531,11 +3427,9 @@ ||onedrive.live.com/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21109&authkey=ap-okubj9bvtlc0$all ||onedrive.live.com/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi$all ||onedrive.live.com/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e$all -||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90$all ||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c$all ||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90$all ||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c$all -||onedrive.live.com/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk$all ||onedrive.live.com/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4$all ||onedrive.live.com/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo$all ||onedrive.live.com/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2!517&authkey=akfewcyiwlwomyk$all @@ -3566,7 +3460,6 @@ ||onedrive.live.com/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21305&authkey=an-uuhplpk2zp5u$all ||onedrive.live.com/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu$all ||onedrive.live.com/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i$all -||onedrive.live.com/download?cid=70d8fa75c83fbdbe&resid=70d8fa75c83fbdbe%21144&authkey=acw8wl1noncfp-4$all ||onedrive.live.com/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam$all ||onedrive.live.com/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble$all ||onedrive.live.com/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60$all @@ -3589,6 +3482,7 @@ ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum$all ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto$all ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum$all +||onedrive.live.com/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm$all ||onedrive.live.com/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125570&authkey=aejqgjglwurnb0a$all ||onedrive.live.com/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq$all ||onedrive.live.com/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k$all @@ -3599,9 +3493,6 @@ ||onedrive.live.com/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny$all ||onedrive.live.com/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s$all ||onedrive.live.com/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs$all -||onedrive.live.com/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli$all -||onedrive.live.com/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18$all -||onedrive.live.com/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli$all ||onedrive.live.com/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm$all ||onedrive.live.com/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8$all ||onedrive.live.com/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm$all @@ -3627,8 +3518,8 @@ ||onedrive.live.com/download?cid=907247dc330a3f33&resid=907247dc330a3f33!254&authkey=ajt5wxegbvzbwqa$all ||onedrive.live.com/download?cid=907247dc330a3f33&resid=907247dc330a3f33!255&authkey=aaimhpp89qmcfhc$all ||onedrive.live.com/download?cid=907247dc330a3f33&resid=907247dc330a3f33%21254&authkey=ajt5wxegbvzbwqa$all -||onedrive.live.com/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s$all ||onedrive.live.com/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my$all +||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc$all ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby$all ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo$all ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti$all @@ -3636,27 +3527,11 @@ ||onedrive.live.com/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8$all ||onedrive.live.com/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o$all ||onedrive.live.com/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!305&authkey=apgh_teb3673nek$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!306&authkey=aibymhcuhqnmrwo$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21305&authkey=apgh_teb3673nek$all ||onedrive.live.com/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m$all ||onedrive.live.com/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w$all ||onedrive.live.com/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk$all ||onedrive.live.com/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk$all ||onedrive.live.com/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k$all -||onedrive.live.com/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli$all ||onedrive.live.com/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm$all ||onedrive.live.com/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue$all ||onedrive.live.com/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma$all @@ -3675,7 +3550,6 @@ ||onedrive.live.com/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8$all ||onedrive.live.com/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq$all ||onedrive.live.com/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq$all -||onedrive.live.com/download?cid=9fb622acb27482ef&resid=9fb622acb27482ef%211197&authkey=aeacibxy2zlyxro$all ||onedrive.live.com/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o$all ||onedrive.live.com/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4$all ||onedrive.live.com/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi$all @@ -3688,7 +3562,6 @@ ||onedrive.live.com/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs$all ||onedrive.live.com/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw$all ||onedrive.live.com/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o$all -||onedrive.live.com/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc$all ||onedrive.live.com/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs$all ||onedrive.live.com/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw$all ||onedrive.live.com/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu$all @@ -3766,9 +3639,6 @@ ||onedrive.live.com/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs$all ||onedrive.live.com/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m$all ||onedrive.live.com/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga$all -||onedrive.live.com/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk$all -||onedrive.live.com/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!362&authkey=alycl9izrvfl7oc$all -||onedrive.live.com/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21362&authkey=alycl9izrvfl7oc$all ||onedrive.live.com/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg$all ||onedrive.live.com/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a$all ||onedrive.live.com/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a$all @@ -3822,6 +3692,7 @@ ||onedrive.live.com/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu$all ||onedrive.live.com/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu$all ||onedrive.live.com/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq$all +||onedrive.live.com/download?cid=e627fc797baa3032&resid=e627fc797baa3032!2324&authkey=aa8i-r7ixmcraha$all ||onedrive.live.com/download?cid=e627fc797baa3032&resid=e627fc797baa3032%212324&authkey=aa8i-r7ixmcraha$all ||onedrive.live.com/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke$all ||onedrive.live.com/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom$all @@ -3836,7 +3707,6 @@ ||onedrive.live.com/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw$all ||onedrive.live.com/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw$all ||onedrive.live.com/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai$all -||onedrive.live.com/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc$all ||onedrive.live.com/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8$all ||onedrive.live.com/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns$all ||onedrive.live.com/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8$all @@ -3846,7 +3716,6 @@ ||onedrive.live.com/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa$all ||onedrive.live.com/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4$all ||onedrive.live.com/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8$all -||onedrive.live.com/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa$all ||onedrive.live.com/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0$all ||onedrive.live.com/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw$all ||onedrive.live.com/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e$all @@ -3855,7 +3724,6 @@ ||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k$all ||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie$all ||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c$all -||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g$all ||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta$all ||onedrive.live.com/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o$all ||onedrive.live.com/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao$all @@ -3875,6 +3743,7 @@ ||onedrive.live.com/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0$all ||onedrive.live.com/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc$all ||onedrive.live.com/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu$all +||onedrive.live.com/download?cid=fd67fafc46d3c687&resid=fd67fafc46d3c687%21473&authkey=aoid_cp-jgffqvm$all ||onedrive.live.com/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm$all ||onedrive.live.com/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w$all ||onedrive.live.com/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm$all @@ -3894,9 +3763,11 @@ ||onedrive.live.com/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta$all ||online.creedglobal.in$all ||onlinestatis.bar$all +||open.rawntech.com$all ||open.warehousesaas.co.uk$all ||opentoronto.org$all ||opolis.io$all +||opticaoptigral.cl$all ||optimus.com.sg$all ||order.bizpeed.com$all ||orientgatewayltd.com$all @@ -3922,7 +3793,6 @@ ||partharaj.me$all ||partsapp.com.br$all ||paste.ee/r/a39ev$all -||paste.ee/r/oitkz$all ||pastebin.com/raw/77jhk0iw$all ||pastebin.com/raw/89hkc7wb$all ||pastebin.com/raw/yqvsvlvq$all @@ -3939,6 +3809,7 @@ ||pd.oceaniarp.net$all ||pemdodo.com$all ||perfumeriamontes.es$all +||periodiche.bar$all ||perpus.onlineman7-jombang.sch.id$all ||perpustekim.untirta.ac.id$all ||pestoclean.co.uk$all @@ -3960,6 +3831,7 @@ ||pointactionsg.com$all ||pokojewewladyslawowie.pl$all ||pole.com.vc$all +||ponchokhana.com$all ||pool.phxdir.com$all ||pooltablemoversdenver.net$all ||portal.premiumpunch.com$all @@ -3970,6 +3842,7 @@ ||prestigehomeautomation.net$all ||preview2.behalen.com$all ||prishaartcreations.com$all +||prismaxis.com$all ||procrossover.ru/wp-content/uploads/2020/10/skoda22.jpg$all ||procrossover.ru/wp-content/uploads/2020/10/skodaqq.jpg$all ||production.sparshims.com$all @@ -4040,7 +3913,6 @@ ||resuco.net$all ||rezkabum.ru$all ||rhema.com.sg$all -||richancyber.info$all ||richmondminerals.co.zm$all ||rinaefoundation.org.za$all ||rinkaisystem-ht.com$all @@ -4049,7 +3921,6 @@ ||rkverify.securestudies.com$all ||robertmcardle.com$all ||robertsinclair.net$all -||romanianpoints.com$all ||ronnietucker.co.uk$all ||roomsvc.servegate.kr$all ||roshnijewellery.com$all @@ -4059,7 +3930,6 @@ ||ruisgood.ru$all ||ruwadalkuwait.com$all ||rydchile.cl$all -||s.51shijuan.com$all ||s.thechinesemuslim.com$all ||sac2.11xii.com$all ||sacredscentsonline.com$all @@ -4094,7 +3964,9 @@ ||sericaasia.com$all ||servicemhkd.myvnc.com$all ||servicemhkd80.myvnc.com$all +||serviciovirtual.com.ar$all ||sexologistpakistan.net$all +||seyranikenger.com.tr$all ||sgb.ac.ke$all ||sgessy.com.br$all ||shaheentbfoundation.com$all @@ -4147,6 +4019,7 @@ ||special-key.cf$all ||spent.com.pl$all ||spetsesyachtcharter.gr$all +||spiritualroot.org$all ||spititourism.com$all ||spittinfire.com$all ||sports-net.de$all @@ -4168,14 +4041,14 @@ ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt$all ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt$all ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt$all +||storage.googleapis.com/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt$all ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt$all ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt$all ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg$all -||storage.googleapis.com/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt$all ||storage.googleapis.com/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt$all ||store.ericalgarin.com$all ||stott-thompson.co.uk$all -||streetdemo.yourpageserver.com$all +||stratexec.co.za$all ||suboldesign.com$all ||sumerians.org$all ||sunaryem.com.tr$all @@ -4224,6 +4097,7 @@ ||test.typoten.com$all ||test.wanepghana.org$all ||test1.asistencia247.com$all +||test1.milenial.id$all ||test1.tenplusone.my$all ||test2.basis-web.com$all ||test2.marrenconstruction.ie$all @@ -4248,7 +4122,7 @@ ||theprofinn.com$all ||thesummitpc.net$all ||theurbantutors.com$all -||thientu.net$all +||thirdstringcalifornia.com$all ||thosewebbs.com$all ||thriveink.com$all ||tianangdep.com$all @@ -4258,7 +4132,6 @@ ||timegonebuy.com$all ||tksb.net$all ||tlcc.com.gt$all -||tntmedia.gr$all ||todoapp.cstdevs.com$all ||todocontodo.com.mx$all ||tonydong.com$all @@ -4296,6 +4169,7 @@ ||umwelt-kirchhof.de$all ||unicorpbrunei.com$all ||uniengrisb.com$all +||unisoftcc.com$all ||unyazitelecom.com$all ||upcbpta.com$all ||urbantrapfest.cl$all @@ -4311,7 +4185,9 @@ ||vcah.co.uk$all ||vectarts.com$all ||vegadelcasero.cl$all +||velma-harber30ku.com$all ||vendas.lidiacarmeli.com.br$all +||versualstudio.com$all ||veterinariadrpopui.com$all ||vfocus.net$all ||vienen.gblix.srv.br$all @@ -4340,6 +4216,7 @@ ||w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu$all ||wanepliberia.org$all ||wanepniger.org$all +||weareactum.com$all ||web.eng.ubu.ac.th$all ||web.geetle.ga$all ||web.geomegasoft.net$all @@ -4375,6 +4252,7 @@ ||wonderhawaii.com$all ||woodsytech.com$all ||wordpress.saleensuporte.com.br$all +||workingsolutionsrome.org$all ||wozata.000webhostapp.com$all ||wp.readhere.in$all ||wpdemo.101clients.com.au$all @@ -4396,7 +4274,7 @@ ||yourclub1.com$all ||yourtopdog.com.au$all ||youtubetrainingacademy.com$all -||yp.hnggzyjy.cn$all +||yp.hnggzyjy.cn/common/yz.vbs$all ||yskadvisors.com$all ||yummyyogaudaipur.com$all ||yzkzixun.com$all diff --git a/urlhaus-filter-ag.txt b/urlhaus-filter-ag.txt index 8d121ad4..70ee9ee5 100644 --- a/urlhaus-filter-ag.txt +++ b/urlhaus-filter-ag.txt @@ -1,5 +1,5 @@ ! Title: Malicious URL Blocklist (AdGuard) -! Updated: Sat, 03 Apr 2021 00:13:46 UTC +! Updated: Sat, 03 Apr 2021 12:12:28 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -2024,6 +2024,7 @@ ||101.109.78.164$all ||101.109.85.37$all ||101.109.85.40$all +||101.126.102.31$all ||101.126.155.223$all ||101.126.87.66$all ||101.128.72.166$all @@ -3771,6 +3772,7 @@ ||103.217.123.137$all ||103.217.123.14$all ||103.217.123.142$all +||103.217.123.143$all ||103.217.123.145$all ||103.217.123.147$all ||103.217.123.151$all @@ -4420,6 +4422,7 @@ ||103.41.25.189$all ||103.41.25.201$all ||103.41.25.203$all +||103.41.25.206$all ||103.41.25.21$all ||103.41.25.212$all ||103.41.25.233$all @@ -12059,6 +12062,7 @@ ||111.92.80.176$all ||111.92.80.182$all ||111.92.80.183$all +||111.92.80.192$all ||111.92.80.195$all ||111.92.80.196$all ||111.92.80.20$all @@ -20048,6 +20052,7 @@ ||112.80.215.101$all ||112.80.215.227$all ||112.80.215.229$all +||112.80.218.56$all ||112.80.236.136$all ||112.80.236.158$all ||112.80.236.45$all @@ -50019,6 +50024,7 @@ ||115.56.130.27$all ||115.56.130.30$all ||115.56.130.32$all +||115.56.130.33$all ||115.56.130.5$all ||115.56.130.52$all ||115.56.130.55$all @@ -93131,6 +93137,7 @@ ||116.68.97.187$all ||116.68.97.192$all ||116.68.97.193$all +||116.68.97.199$all ||116.68.97.2$all ||116.68.97.204$all ||116.68.97.212$all @@ -116914,6 +116921,7 @@ ||117.202.69.110$all ||117.202.69.111$all ||117.202.69.112$all +||117.202.69.113$all ||117.202.69.114$all ||117.202.69.115$all ||117.202.69.116$all @@ -118555,6 +118563,7 @@ ||117.208.135.217$all ||117.208.135.218$all ||117.208.135.22$all +||117.208.135.220$all ||117.208.135.225$all ||117.208.135.227$all ||117.208.135.229$all @@ -119414,6 +119423,7 @@ ||117.212.52.160$all ||117.212.54.132$all ||117.212.55.67$all +||117.213.10.108$all ||117.213.10.115$all ||117.213.10.125$all ||117.213.10.140$all @@ -119468,6 +119478,7 @@ ||117.213.15.238$all ||117.213.15.29$all ||117.213.15.43$all +||117.213.15.72$all ||117.213.40.10$all ||117.213.40.100$all ||117.213.40.102$all @@ -120940,6 +120951,7 @@ ||117.215.208.107$all ||117.215.208.11$all ||117.215.208.116$all +||117.215.208.14$all ||117.215.208.143$all ||117.215.208.149$all ||117.215.208.153$all @@ -123260,6 +123272,7 @@ ||117.222.169.229$all ||117.222.169.23$all ||117.222.169.231$all +||117.222.169.232$all ||117.222.169.234$all ||117.222.169.236$all ||117.222.169.239$all @@ -129855,6 +129868,7 @@ ||118.24.9.62$all ||118.246.199.1$all ||118.246.246.125$all +||118.246.38.170$all ||118.249.136.112$all ||118.249.136.98$all ||118.249.137.218$all @@ -151900,6 +151914,7 @@ ||123.14.248.189$all ||123.14.248.19$all ||123.14.248.208$all +||123.14.248.210$all ||123.14.248.212$all ||123.14.248.216$all ||123.14.248.221$all @@ -153322,6 +153337,7 @@ ||123.159.30.49$all ||123.159.31.110$all ||123.159.51.112$all +||123.159.68.119$all ||123.159.68.151$all ||123.159.68.26$all ||123.159.68.31$all @@ -153598,6 +153614,7 @@ ||123.191.6.244$all ||123.191.6.93$all ||123.191.60.197$all +||123.191.62.239$all ||123.191.63.187$all ||123.191.7.209$all ||123.191.79.120$all @@ -162359,7 +162376,7 @@ ||123moviesfx.com$all ||123sellfast.com$all ||123sex.co$all -||123tadi.com$all +||123tadi.com/invoice-status/invoice-0321355444-jun-20$all ||123xyz.xyz$all ||124.100.74.153$all ||124.105.105.222$all @@ -202119,6 +202136,7 @@ ||178.141.47.227$all ||178.141.47.70$all ||178.141.48.109$all +||178.141.48.178$all ||178.141.48.43$all ||178.141.48.82$all ||178.141.49.101$all @@ -202600,6 +202618,7 @@ ||178.175.100.58$all ||178.175.100.61$all ||178.175.100.65$all +||178.175.100.7$all ||178.175.100.70$all ||178.175.100.75$all ||178.175.100.77$all @@ -202779,6 +202798,7 @@ ||178.175.102.211$all ||178.175.102.214$all ||178.175.102.216$all +||178.175.102.219$all ||178.175.102.22$all ||178.175.102.220$all ||178.175.102.221$all @@ -203910,6 +203930,7 @@ ||178.175.112.136$all ||178.175.112.138$all ||178.175.112.139$all +||178.175.112.140$all ||178.175.112.147$all ||178.175.112.148$all ||178.175.112.15$all @@ -206285,6 +206306,7 @@ ||178.175.18.27$all ||178.175.18.32$all ||178.175.18.36$all +||178.175.18.37$all ||178.175.18.38$all ||178.175.18.42$all ||178.175.18.45$all @@ -209022,7 +209044,9 @@ ||178.175.43.217$all ||178.175.43.22$all ||178.175.43.220$all +||178.175.43.223$all ||178.175.43.227$all +||178.175.43.229$all ||178.175.43.231$all ||178.175.43.232$all ||178.175.43.234$all @@ -209109,6 +209133,7 @@ ||178.175.44.158$all ||178.175.44.162$all ||178.175.44.165$all +||178.175.44.166$all ||178.175.44.168$all ||178.175.44.169$all ||178.175.44.171$all @@ -212139,6 +212164,7 @@ ||178.175.71.174$all ||178.175.71.175$all ||178.175.71.178$all +||178.175.71.179$all ||178.175.71.180$all ||178.175.71.185$all ||178.175.71.189$all @@ -212862,6 +212888,7 @@ ||178.175.78.234$all ||178.175.78.236$all ||178.175.78.240$all +||178.175.78.242$all ||178.175.78.243$all ||178.175.78.244$all ||178.175.78.246$all @@ -214980,6 +215007,7 @@ ||178.175.97.110$all ||178.175.97.111$all ||178.175.97.112$all +||178.175.97.113$all ||178.175.97.116$all ||178.175.97.118$all ||178.175.97.12$all @@ -217505,6 +217533,7 @@ ||180.188.241.194$all ||180.188.241.2$all ||180.188.241.201$all +||180.188.241.203$all ||180.188.241.215$all ||180.188.241.216$all ||180.188.241.219$all @@ -240023,6 +240052,7 @@ ||182.121.26.242$all ||182.121.26.251$all ||182.121.26.35$all +||182.121.26.37$all ||182.121.26.56$all ||182.121.26.58$all ||182.121.26.77$all @@ -272694,6 +272724,7 @@ ||202.164.138.185$all ||202.164.138.187$all ||202.164.138.188$all +||202.164.138.19$all ||202.164.138.192$all ||202.164.138.195$all ||202.164.138.196$all @@ -277293,6 +277324,7 @@ ||209.14.30.183$all ||209.14.30.204$all ||209.14.30.205$all +||209.14.30.209$all ||209.14.30.212$all ||209.14.30.213$all ||209.14.30.216$all @@ -277319,6 +277351,7 @@ ||209.14.31.190$all ||209.14.31.192$all ||209.14.31.201$all +||209.14.31.209$all ||209.14.31.215$all ||209.14.31.217$all ||209.14.31.220$all @@ -277331,6 +277364,7 @@ ||209.14.31.243$all ||209.14.31.244$all ||209.14.31.247$all +||209.14.31.249$all ||209.14.31.252$all ||209.14.31.253$all ||209.14.31.55$all @@ -277899,6 +277933,7 @@ ||210.18.189.89$all ||210.18.189.9$all ||210.18.189.90$all +||210.180.17.140$all ||210.180.237.212$all ||210.182.101.144$all ||210.182.148.126$all @@ -290874,6 +290909,7 @@ ||220.133.1.130$all ||220.133.103.166$all ||220.133.109.249$all +||220.133.110.157$all ||220.133.114.189$all ||220.133.115.57$all ||220.133.117.229$all @@ -316650,6 +316686,7 @@ ||27.210.29.26$all ||27.210.29.83$all ||27.210.3.50$all +||27.210.32.122$all ||27.210.32.123$all ||27.210.32.125$all ||27.210.32.130$all @@ -318093,6 +318130,7 @@ ||27.216.116.240$all ||27.216.116.81$all ||27.216.117.178$all +||27.216.117.54$all ||27.216.118.234$all ||27.216.119.219$all ||27.216.119.228$all @@ -347342,6 +347380,7 @@ ||36.248.227.203$all ||36.248.228.64$all ||36.248.82.234$all +||36.248.83.98$all ||36.248.88.35$all ||36.248.92.154$all ||36.248.93.13$all @@ -362825,6 +362864,7 @@ ||42.226.83.71$all ||42.226.83.78$all ||42.226.83.98$all +||42.226.85.236$all ||42.226.86.204$all ||42.226.87.123$all ||42.226.88.114$all @@ -365116,6 +365156,7 @@ ||42.228.39.197$all ||42.228.39.2$all ||42.228.39.204$all +||42.228.39.211$all ||42.228.39.212$all ||42.228.39.214$all ||42.228.39.215$all @@ -372867,6 +372908,7 @@ ||42.232.81.147$all ||42.232.81.149$all ||42.232.81.176$all +||42.232.81.179$all ||42.232.81.181$all ||42.232.81.183$all ||42.232.81.188$all @@ -387106,6 +387148,7 @@ ||49.117.191.46$all ||49.117.191.78$all ||49.117.191.83$all +||49.119.187.230$all ||49.119.188.56$all ||49.119.189.124$all ||49.119.189.223$all @@ -390804,6 +390847,7 @@ ||58.248.142.212$all ||58.248.142.214$all ||58.248.142.223$all +||58.248.142.227$all ||58.248.142.23$all ||58.248.142.230$all ||58.248.142.236$all @@ -392043,6 +392087,7 @@ ||58.249.79.16$all ||58.249.79.163$all ||58.249.79.17$all +||58.249.79.174$all ||58.249.79.175$all ||58.249.79.188$all ||58.249.79.195$all @@ -392239,6 +392284,7 @@ ||58.249.84.118$all ||58.249.84.124$all ||58.249.84.128$all +||58.249.84.131$all ||58.249.84.134$all ||58.249.84.148$all ||58.249.84.150$all @@ -403737,6 +403783,7 @@ ||59.96.37.121$all ||59.96.37.122$all ||59.96.37.123$all +||59.96.37.124$all ||59.96.37.125$all ||59.96.37.127$all ||59.96.37.128$all @@ -408159,6 +408206,7 @@ ||59.99.43.187$all ||59.99.43.19$all ||59.99.43.190$all +||59.99.43.191$all ||59.99.43.192$all ||59.99.43.193$all ||59.99.43.194$all @@ -430994,6 +431042,7 @@ ||61.53.89.199$all ||61.53.89.2$all ||61.53.89.208$all +||61.53.89.220$all ||61.53.89.221$all ||61.53.89.227$all ||61.53.89.232$all @@ -432072,6 +432121,7 @@ ||61.54.69.62$all ||61.54.69.69$all ||61.54.69.70$all +||61.54.69.77$all ||61.54.69.78$all ||61.54.69.8$all ||61.54.69.95$all @@ -446658,7 +446708,7 @@ ||app.boxrcdn.com$all ||app.bridgeimpex.org$all ||app.calag.at$all -||app.casetabs.com$all +||app.casetabs.com/n/p7nx8575$all ||app.catholicchurch.co.in$all ||app.choiphui.com$all ||app.cloudindustry.net$all @@ -451118,6 +451168,7 @@ ||beansmedia.com$all ||beanssur.com$all ||beantreefoods.com$all +||beanx88.xyz$all ||beanz-network.com$all ||bearcatpumps.com.cn$all ||beard-companies.com$all @@ -458909,7 +458960,7 @@ ||cdnpic.mgyun.com$all ||cdnrep.reimage.com/prot/protectorpackagerr2023.exe$all ||cdnrep.reimage.com/ver/reimagepackage1874x64b.exe$all -||cdnrep.reimageplus.com$all +||cdnrep.reimageplus.com/rqt/reimagerepair.exe$all ||cdnxh.net$all ||cdoconsult.com.br$all ||cdolechon.com$all @@ -459665,7 +459716,7 @@ ||cheapgadgets-gq.000webhostapp.com$all ||cheapistan.pk$all ||cheapmlbjerseysmarlins.com$all -||cheapmusic.info$all +||cheapmusic.info/cloudnet.exe$all ||cheapnikeairmaxshoes-online.com/0866x/sep/business$all ||cheapnikeairmaxshoes-online.com/0866x/sep/business/$all ||cheapnikeairmaxshoes-online.com/eri8g1mtcmqdynau9plb/swift/200-jahre$all @@ -459722,7 +459773,7 @@ ||cheematransxpressinc.com$all ||cheerchile.cl$all ||cheerfulgiversneverlack.com$all -||cheerfullydo.com$all +||cheerfullydo.com/data/nhtlrr/94046/nbar_94046_29052020.zip$all ||cheesecakery.com.br$all ||cheetahridge.mediadevstaging.com$all ||chef-solutions.dreamscape.co.in$all @@ -460170,8 +460221,7 @@ ||christinablunsum.com$all ||christinailoveyousomuchyoumyheart.duckdns.org$all ||christinalenway.com$all -||christinekeller.ch/wp-content/uploads/document/840880756/0s7m3d-40676/$all -||christinekeller.ch/wp-content/uploads/eo4iqgqw-nb3k8-4084/$all +||christinekeller.ch$all ||christinelebeck.com$all ||christinewalker.org/wp-admin/xt9snhtexu/$all ||christinmunsch.com$all @@ -466012,7 +466062,7 @@ ||demo.jrkcompany.com$all ||demo.kalapifoods.com$all ||demo.kanapebudapest.hu$all -||demo.kechuahangdidong.com/assets/file/h-585-50-xjfl8wz-oariqb/$all +||demo.kechuahangdidong.com$all ||demo.kzonetechnologies.com$all ||demo.lamppostmedia.in$all ||demo.lapizblanco.com$all @@ -468176,7 +468226,8 @@ ||dl-675423.store-downloads.com$all ||dl-80076342.md-downloads.com$all ||dl-97674424.md-downloads.com$all -||dl-gameplayer.dmm.com$all +||dl-gameplayer.dmm.com/product/apkggame/giga_baldrbringerextendcode/giga_baldrbringerextendcode/win/src/content/data/data/uninstall.exe$all +||dl-gameplayer.dmm.com/product/apkggame/nel_narikiri/nel_narikiri/win/src/content/data/%e3%81%aa%e3%82%8a%e3%81%8d%e3%82%8a%e3%83%90%e3%82%ab%e3%83%83%e3%83%97%e3%83%ab%ef%bc%81.exe$all ||dl-link.link$all ||dl-link.live$all ||dl-link.network$all @@ -468504,7 +468555,7 @@ ||dl.rina-roleplay.com$all ||dl.river-store.com$all ||dl.rp-soft.ir$all -||dl.softservers.net$all +||dl.softservers.net/111000667/optimizerpro.exe%20%20d.tubedimmerapp.com/updater/setup4.exe$all ||dl.svcupdate.com$all ||dl.teeqee.com$all ||dl.x420.me$all @@ -470757,8 +470808,10 @@ ||down.post-gg.top$all ||down.postch-b.top$all ||down.postch-bsw.top$all +||down.postch-de.top$all ||down.postch-dfa.top$all ||down.postch-dj.top$all +||down.postch-dl.top$all ||down.postch-fa.top$all ||down.postch-fj.top$all ||down.postch-kf.top$all @@ -487403,7 +487456,8 @@ ||economiadigital.biz$all ||economika.com.ve$all ||economizei.shop$all -||economplast.com$all +||economplast.com/lypumytb/d4/ce/a64bze4c.zip$all +||economplast.com/lypumytb/ma/25/tt18os7d.zip$all ||economywindowcleaner.com$all ||econoteen.fea.usp.br$all ||econotel.us$all @@ -492360,7 +492414,9 @@ ||files.gamebanana.com/tools/enchanced_server_picker.exe$all ||files.gamebanana.com/tools/tagconverter.exe$all ||files.gathercdn.com$all -||files.hrloo.com$all +||files.hrloo.com/bbs/data/attachment/forum/201212/20/10301044ex3m3s62emr1r7.doc$all +||files.hrloo.com/bbs/data/attachment/forum/201212/20/10301044ex3m3s62emr1r7.doc?n=w+eyvuwtgv3lkzjlt6xln7norq3nrqhnkiblilbluqyuzg9j$all +||files.hrloo.com/bbs/data/attachment/forum/201212/20/10301044ex3m3s62emr1r7.doc?n=weyvuwtgv3lkzjlt6xln7norq3nrqhnkiblilbluqyuzg9j$all ||files.jivosite.com/file-transfer/1621967/2021-03-16/55ec600e4e6500e080c5.doc$all ||files.l-d.tech$all ||files.lashawnbarber.com/$all @@ -494721,8 +494777,7 @@ ||fv13.failiem.lv$all ||fv15.failiem.lv$all ||fv2-1.failiem.lv/down.php?cf&i=hyg2rxaa&n=new_payment.doc&download_checksum=afa67b9a5998eca281cda22f5585e9dcf764128a&download_timestamp=1547330846$all -||fv2-2.failiem.lv/down.php?cf&i=my59dhhv&n=2562.xls$all -||fv2-2.failiem.lv/down.php?cf&i=redm59qf&n=dfg-016.xls$all +||fv2-2.failiem.lv$all ||fv2-7.failiem.lv$all ||fv3.failiem.lv$all ||fv6.failiem.lv$all @@ -499232,7 +499287,7 @@ ||hangtrentroi.com$all ||hangulcafes.ga$all ||hanh.cz$all -||hanhtrinhtamlinh.com$all +||hanhtrinhtamlinh.com/gpk/personal-section/verifiable-space/d3d-660ut9x793v61/$all ||hanhtrinhthanhnienkhoinghiep.vn$all ||haniamarket.com$all ||hanict.org.vn$all @@ -499435,7 +499490,8 @@ ||harriscustomcatering.com$all ||harrisheatpumps.nz$all ||harrisnewtech.ir$all -||harrisoncarter.com$all +||harrisoncarter.com/3578001584444_ycu75_resource/kkc/$all +||harrisoncarter.com/3578001584444_ycu75_resource/yzgvvr/$all ||harrisonlily.co.uk$all ||harryfang.com$all ||harryhiggins.com$all @@ -502353,7 +502409,7 @@ ||i.cubeupload.com/euev6n.jpg$all ||i.cubeupload.com/ez3vpt.jpg$all ||i.cubeupload.com/gmetap.jpg$all -||i.fiery.me$all +||i.fiery.me/5vdk.png$all ||i.fluffy.cc$all ||i.funtourspt.eu$all ||i.imgur.com/3zblzb6.png$all @@ -508974,8 +509030,7 @@ ||kec-cendana.enrekangkab.go.id$all ||kec-wlingi.blitarkab.go.id$all ||kecforging.com$all -||kechuahangdidong.com/wp-admin/esp/0ebq5jmrn3i6/6qh4jn-346396224-48-1pa3isys-ble49fo32t5/$all -||kechuahangdidong.com/wp-admin/mncrbbx/6xpzk58cu/4-4637795257-79951-vdhdt1n26o-r0w7n/$all +||kechuahangdidong.com$all ||keciorenkoltukyikama.net$all ||keckarangdadap.pekalongankab.go.id$all ||kecsfila.hu$all @@ -530191,23 +530246,7 @@ ||ossandonycia.cl$all ||osscaar.com$all ||osservatore.betacom.it$all -||ossi4.51cto.com/attachment/201203/4594712_1333015433.rar$all -||ossi4.51cto.com/attachment/201204/4594712_1334794324.rar$all -||ossi4.51cto.com/attachment/201204/4594712_1335670976.rar$all -||ossi4.51cto.com/attachment/201205/4594712_1336127240.rar$all -||ossi4.51cto.com/attachment/201205/4594712_1337420961.rar$all -||ossi4.51cto.com/attachment/201205/4594712_1337853814.rar$all -||ossi4.51cto.com/attachment/201205/4594712_1337902068.rar$all -||ossi4.51cto.com/attachment/201205/4594712_1338219299.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1338596584.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1338631130.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1338940618.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1339042034.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1339151181.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1339214458.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1339410537.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1339456815.rar$all -||ossi4.51cto.com/attachment/201206/5305206_1339979954.rar$all +||ossi4.51cto.com$all ||ossianlaw.com$all ||osslusturv.com$all ||ossoriobouliz.com$all @@ -539673,7 +539712,7 @@ ||politrix.net$all ||poliyzsl.host$all ||poljimenez.com$all -||polk.k12.ga.us/userfiles/13/classes/2473/8thpssyllabus.doc$all +||polk.k12.ga.us$all ||polka32.ru$all ||polkapower.com$all ||polkolonieb4k.pl$all @@ -540873,7 +540912,8 @@ ||professionalwaiterskollege.org$all ||professionelelit.com$all ||professorsgallery.com$all -||profetestruec.net$all +||profetestruec.net:8000/in3.ps1$all +||profetestruec.net:8000/in6.ps1$all ||profexsystem.com$all ||proffessia.ru$all ||proffice.com.pl$all @@ -541264,9 +541304,7 @@ ||protect-us.mimecast.com/s/7ihcc82oqycqx96qh15qw5$all ||protect-us.mimecast.com/s/c27ac0rx9ru80p3fw0bgj$all ||protect-us.mimecast.com/s/qki9c73wxjupxq5ps8qcm_$all -||protect.mimecast-offshore.com/s/ip17cn9blzfnq4n4h4tudd?domain=meraqsa.com/$all -||protect.mimecast-offshore.com/s/loqwcg5rvpcjndxqc76apn?domain=ronakfence.ir/$all -||protect.mimecast-offshore.com/s/rd0zcjqxyvf8w6o3igppxq?domain=ronakfence.ir/$all +||protect.mimecast-offshore.com$all ||protect2.fireeye.com/v1/url?k=59eacb3c-0560e9d5-59ed97de-0cc47ad93e2e-0f5e34e79adab692&q=1&e=e7991bbc-cc93-4814-a8f2-fd6d6950b0d5&u=https%3a%2f%2fwww.mediafire.com%2ffile%2fs2uyxs8t8kbuyye%2fdocumentos_de_env%25cdo.7z%2ffile$all ||protect2.fireeye.com/v1/url?k=6d0c09d2-33bdd2b2-6d0f7943-86e2237f51fb-ab55eb53c2dfee1f&q=1&e=358c9b57-d351-4b0f-80cf-d0755ec21127&u=https://pottershousedurban.co.za/cgi-bin/file/xzbx0cb5wywuw5/179vj6b9dpsp7advozp/$all ||protectiadatelor.biz$all @@ -549985,7 +550023,7 @@ ||shared.outlook.inky.com/link?domain=www.toziba.ir&t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdunfugkaq_jd7tqby28qtte2siucq4akhiquccnh36heusom_93hq0odndjazm7p7jrqbtgtkoxmvihjsn4atsxnae0sfiliaq_yjwemmigieajwaghr4flxxomyqraaocn-olxohlupdgzsxe7prokpvd5qbqawg1wcoobwjkz3ufhzxrsqdhoeov97zesjd3ud42czjzno6tbykppb0q2sllrejuqukofjgvoh2meqyo3nmwrvhrrxjjy_wjowcvdf-eyutqxtbpcsvrxzwosy4xzirljn8gab75zz7x9l-wuzbwemg7on1all8m9bux-5uz2yu_7siifpeuvfexnqvcu5-4aze-6xfvs5svlghmixjb1iockmarmeqzkscgzgr_7818pqjn19jvyhz.meyciqdjb9hlkixl4sz_rt8-tj8v7t6tzcbxfjgcuyhbc8ixuwihapwstswmgpu_k43h-va03ffjltif7n-k3qrucylug8il/$all ||shared.outlook.inky.com/link?domain=www.toziba.ir/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxduf1vgjau_s99dqa4t-mtbcbortbrpqqhireoqmmllilisv--8rrkj-fm3pp1jrqbxuzogu6lajgr-gscydidneklueqkyghxataqeskap0d1icdpx5-xhepmyfztb4u_1er9gwqlls0inmoz6zpd1y8ybaougl6eioelie1pd1fvuhzk2mfxau_wb173mbp_9kvnloytl6c1ida15m5hc9eynkkqkaruwsinajexjjmyy87akjxrhm55fe5yxhmndvmrtoiww3ewve8cwlmrcpelfi7smoghdistd2_pyu4jwk0iz-ncvdrjbzn2vt13vv4de76-4cqhacp8i-kpt7tl7cfos3vxc_otje5d44bihawljjdnkjsnzktprjwzkcv_2xpzzdhpl9e5g6k.meucigd6xwariut2lkiettiajcosxyluv7ub6nhbepewswmwaiea4mzpunjaca7lslweyqnda4gpvqjwhufuenzur1jmp64//$all ||shared.outlook.inky.com/link?domain=www.toziba.ir/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdunfugkaq_jd7tqby28qtte2siucq4akhiquccnh36heusom_93hq0odndjazm7p7jrqbtgtkoxmvihjsn4atsxnae0sfiliaq_yjwemmigieajwaghr4flxxomyqraaocn-olxohlupdgzsxe7prokpvd5qbqawg1wcoobwjkz3ufhzxrsqdhoeov97zesjd3ud42czjzno6tbykppb0q2sllrejuqukofjgvoh2meqyo3nmwrvhrrxjjy_wjowcvdf-eyutqxtbpcsvrxzwosy4xzirljn8gab75zz7x9l-wuzbwemg7on1all8m9bux-5uz2yu_7siifpeuvfexnqvcu5-4aze-6xfvs5svlghmixjb1iockmarmeqzkscgzgr_7818pqjn19jvyhz.meyciqdjb9hlkixl4sz_rt8-tj8v7t6tzcbxfjgcuyhbc8ixuwihapwstswmgpu_k43h-va03ffjltif7n-k3qrucylug8il//$all -||shared.pdffiller.com$all +||shared.pdffiller.com/1395f7beaf30f1943ac9e1b9800a8fbf/8c7dd922ad47494fc02c388e12c00eac/cdecfead5bd78cb1c29f931bc49ad2db.exe?t=1549302986$all ||shareddocuments.ml$all ||shareddynamics.com$all ||sharedeconomy.eu$all @@ -557423,7 +557461,7 @@ ||supadom.fr$all ||supamidland-my.sharepoint.com$all ||supcargo.com$all -||supdate.mediaweb.co.kr/download/pica/client/data/uninstall_1.exe$all +||supdate.mediaweb.co.kr$all ||super-filtr.ru$all ||super-gamezer.com$all ||super-industries.co$all @@ -562215,7 +562253,7 @@ ||tldrnet.top/winsysdrv.exe$all ||tlextreme.com$all ||tlfthelifefactory.com.au$all -||tlgur.com$all +||tlgur.com/d/8lop0bv4/$all ||tlkcloudem.com$all ||tlktdsfj.sha58.me$all ||tlpclient.site$all @@ -563935,7 +563973,7 @@ ||tsr-mark.xyz$all ||tsredco.telangana.gov.in$all ||tsrj.monster$all -||tsrv2.top/telikkk.exe$all +||tsrv2.top$all ||tsrv4.ws/23.exe$all ||tst.marineindust.com$all ||tstfrigo.com$all @@ -566022,9 +566060,7 @@ ||update-prog.com$all ||update-res.100public.com$all ||update.5v.pl$all -||update.7h4uk.com:443/antitrojan.ps1$all -||update.7h4uk.com:443/cohernece.txt$all -||update.7h4uk.com:443/logos.png$all +||update.7h4uk.com$all ||update.att.tools$all ||update.bracncet.net$all ||update.bruss.org.ru$all @@ -566315,7 +566351,7 @@ ||url.emailprotection.link/?bgmvicpuho15c9_q9hiofgnmkaco0q_lujjcaeowkfik_hdtt1uqmbkpovhxykckgjoqoytv_u0g2umkhd4mbi9ms8vo3vliq2clouuaa6no2a7ij5ljfsouoeememvmi/$all ||url.emailprotection.link/?bizyxbw1fdagsfcc1n6ep1awpdx9dr0brnjjqwgyaofpw98limviipvrszjnzzluclpeqqdywfxwnwudvwrljcufuhl2_nha0bs8wz9jmbahcciikbseljewayzbe_cnd/$all ||url.sg/rwtho$all -||url2.mailanyone.net/v1/?m=1hibcm-0003zv-63&i=57e1b682&c=sb1blj46bk32u6f729r5t_slvkx-heewxh20_zdn9-3ktcc0-kn35fykilpydgeyvrbwqwb5h__fk383wtdakqftjlelxz06jbaglri5jmujnydjkasqxwdtg2hn-_be1dzrnthvvhigyhm_tvbew342habp8dtit9jjlieuc2x-ipgdgipe7y_c9jhe69532gmnxozb5wifjfbstzicagmtpg6yxmreaf0sq2dgo-ksy54hetfhn6gwm4kiw2vvcqx17a9bm6ykn8bwpwdjwg/$all +||url2.mailanyone.net$all ||url3.mailanyone.net$all ||url5459.41southbar.com$all ||url675.textilmallorca.com$all @@ -567781,7 +567817,7 @@ ||viettrust-vn.net$all ||vietucgroup.org$all ||vietup.net$all -||vietvictory.vn$all +||vietvictory.vn/wp-content/themes/eikra-child/languages/1c.jpg$all ||vievioparapija.eu$all ||view-indonesia.com$all ||view-your-website.com$all @@ -568240,8 +568276,7 @@ ||visualblends.com$all ||visualdata.ru$all ||visualdimensioniq.com$all -||visualdive.com/wp-admin/balance/4343726113/u2r5u-00497429/$all -||visualdive.com/wp-content/k8kibhjxoc03akqd0hampdubw8dg8zgiuo3pcqu6lbns5b5yrs4ky/$all +||visualdive.com$all ||visualendodontics.net$all ||visualgag.co.uk$all ||visualhome.cl$all @@ -569359,7 +569394,7 @@ ||wc3prince.ru$all ||wcare.nl$all ||wcbgroup.co.uk$all -||wcdownloadercdn.lavasoft.com$all +||wcdownloadercdn.lavasoft.com/4.3.1908.3686/wcinstaller.exe$all ||wcdr.pbas.es$all ||wcf-old.sibcat.info$all ||wcfamlaw.com$all @@ -571088,6 +571123,7 @@ ||workingonit.site$all ||workingpainters.com$all ||workingroofers.com$all +||workingsolutionsrome.org$all ||workingwell.club$all ||worklinic.com.br$all ||workmate-sien.com$all @@ -573549,7 +573585,7 @@ ||yoyoso.nz$all ||yoyoteacher.cn$all ||yp.dcyazilim.com$all -||yp.hnggzyjy.cn$all +||yp.hnggzyjy.cn/common/yz.vbs$all ||ypbb.or.id$all ||ypddf.org$all ||ypicsdy.cf$all @@ -574534,8 +574570,7 @@ ||zoox.com.br$all ||zoparo.nl$all ||zopbxtjiuykhyyp.usa.cc$all -||zopro.duckdns.org/cbsmsg.zip$all -||zopro.duckdns.org/cbsmsg1.zip$all +||zopro.duckdns.org$all ||zoracle.com$all ||zorancreative.com$all ||zoratech.ro$all diff --git a/urlhaus-filter-agh-online.txt b/urlhaus-filter-agh-online.txt index 2aa12933..8092fd1a 100644 --- a/urlhaus-filter-agh-online.txt +++ b/urlhaus-filter-agh-online.txt @@ -1,5 +1,5 @@ ! Title: Online Malicious URL Blocklist (AdGuard Home) -! Updated: Sat, 03 Apr 2021 00:13:46 UTC +! Updated: Sat, 03 Apr 2021 12:12:28 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -7,6 +7,7 @@ ||0-24bpautomentes.hu^ ||0cl.sldov.ru^ ||1.11.234.99^ +||1.186.151.219^ ||1.222.196.60^ ||1.245.4.163^ ||1.246.222.107^ @@ -17,10 +18,8 @@ ||1.246.222.138^ ||1.246.222.14^ ||1.246.222.165^ -||1.246.222.16^ ||1.246.222.20^ ||1.246.222.228^ -||1.246.222.232^ ||1.246.222.234^ ||1.246.222.237^ ||1.246.222.245^ @@ -41,6 +40,7 @@ ||1.246.223.105^ ||1.246.223.109^ ||1.246.223.10^ +||1.246.223.126^ ||1.246.223.127^ ||1.246.223.130^ ||1.246.223.146^ @@ -78,12 +78,10 @@ ||101.73.131.78^ ||101.75.157.99^ ||101.75.167.213^ -||101.99.94.15^ ||102.130.115.14^ ||102.141.240.139^ ||103.113.99.79^ ||103.125.218.107^ -||103.136.82.50^ ||103.141.138.118^ ||103.141.138.12^ ||103.146.174.208^ @@ -92,12 +90,11 @@ ||103.217.215.21^ ||103.224.200.146^ ||103.224.200.40^ -||103.227.118.129^ +||103.237.21.36^ ||103.238.228.4^ ||103.240.249.121^ ||103.4.117.26^ ||103.70.160.51^ -||103.79.112.254^ ||103.82.98.170^ ||103.84.240.130^ ||103.91.245.12^ @@ -142,6 +139,7 @@ ||109.124.90.229^ ||109.233.196.232^ ||109.235.7.228^ +||109.248.58.238^ ||109.86.85.253^ ||109.95.200.102^ ||109.95.200.230^ @@ -155,28 +153,27 @@ ||110.228.195.46^ ||110.241.119.168^ ||110.248.124.254^ +||110.248.175.141^ ||110.248.251.194^ ||110.251.10.18^ ||110.253.150.248^ ||110.253.213.198^ +||110.253.51.112^ ||110.255.101.184^ ||110.255.167.147^ ||110.35.145.127^ ||110.35.208.21^ -||110.35.221.77^ ||110.35.223.92^ ||110.35.225.24^ -||110.35.233.147^ ||110.35.235.57^ +||110.35.249.21^ ||110.35.4.2^ ||110fss.net^ -||111.118.111.207^ ||111.118.41.173^ ||111.118.88.61^ ||111.119.245.114^ ||111.125.67.125^ ||111.165.21.195^ -||111.165.248.134^ ||111.166.236.191^ ||111.167.151.156^ ||111.170.85.71^ @@ -193,22 +190,20 @@ ||111.38.103.66^ ||111.38.104.141^ ||111.38.104.15^ -||111.38.106.128^ ||111.38.106.19^ ||111.38.121.222^ ||111.38.121.223^ ||111.38.121.226^ ||111.38.121.228^ ||111.38.26.243^ +||111.38.8.81^ ||111.61.52.53^ ||112.111.108.184^ -||112.111.31.175^ ||112.133.222.151^ ||112.147.92.51^ ||112.159.108.96^ ||112.163.200.217^ ||112.170.124.75^ -||112.170.233.9^ ||112.186.210.211^ ||112.186.96.252^ ||112.187.91.117^ @@ -262,18 +257,15 @@ ||112.247.81.173^ ||112.247.82.122^ ||112.248.148.90^ -||112.248.179.239^ ||112.248.197.164^ ||112.249.109.217^ ||112.249.118.157^ ||112.249.26.129^ ||112.249.79.98^ ||112.250.102.173^ -||112.250.57.99^ ||112.251.218.210^ ||112.252.136.84^ ||112.252.196.17^ -||112.252.212.122^ ||112.252.221.244^ ||112.252.239.103^ ||112.254.208.123^ @@ -309,7 +301,6 @@ ||112.27.124.177^ ||112.27.124.178^ ||112.27.124.179^ -||112.27.124.71^ ||112.27.127.155^ ||112.27.83.182^ ||112.27.83.23^ @@ -334,7 +325,6 @@ ||112.30.1.91^ ||112.30.110.31^ ||112.30.110.36^ -||112.30.110.37^ ||112.30.110.38^ ||112.30.110.41^ ||112.30.110.43^ @@ -349,21 +339,23 @@ ||112.30.4.136^ ||112.30.4.52^ ||112.31.240.239^ -||112.31.82.160^ ||112.31.87.98^ ||112.53.224.79^ ||112.65.53.175^ +||112.72.153.37^ +||112.72.162.159^ ||112.72.162.49^ ||112.72.162.53^ ||112.72.176.112^ ||112.72.176.84^ -||112.72.231.35^ +||112.72.226.202^ ||112.78.45.158^ ||112.80.117.32^ ||112.80.118.16^ ||112.80.127.91^ ||112.80.207.144^ ||112.80.215.101^ +||112.80.218.56^ ||112.82.146.253^ ||112.82.18.255^ ||112.82.224.139^ @@ -381,16 +373,14 @@ ||113.231.211.131^ ||113.254.169.251^ ||113.59.128.133^ -||113.59.136.39^ +||113.59.133.16^ ||113.59.154.21^ ||113.59.191.47^ ||113.61.204.205^ -||113.87.174.63^ -||113.87.175.135^ -||113.89.42.50^ ||113.89.43.185^ ||113.90.26.136^ -||114.199.204.37^ +||114.111.242.3^ +||114.199.253.235^ ||114.200.154.181^ ||114.224.203.128^ ||114.226.100.56^ @@ -398,31 +388,24 @@ ||114.229.165.194^ ||114.235.115.236^ ||114.30.54.64^ -||114.32.237.100^ ||114.79.172.42^ ||115.165.216.112^ ||115.201.38.185^ ||115.42.47.36^ -||115.48.204.56^ ||115.50.21.56^ ||115.51.125.55^ ||115.52.18.65^ -||115.55.144.42^ -||115.55.145.147^ ||115.55.153.194^ -||115.55.190.144^ ||115.55.60.129^ ||115.56.131.242^ ||115.56.133.96^ ||115.56.144.213^ ||115.56.159.132^ -||115.56.187.173^ ||115.58.132.140^ ||115.58.165.147^ -||115.59.240.217^ ||115.59.255.194^ ||115.61.118.201^ -||115.62.26.39^ +||115.69.102.84^ ||115.73.3.11^ ||115.92.174.231^ ||116.124.219.2^ @@ -431,15 +414,21 @@ ||116.211.100.26^ ||116.212.132.119^ ||116.212.142.215^ -||117.196.49.249^ +||117.194.166.219^ ||117.196.50.107^ ||117.20.204.138^ ||117.20.204.5^ ||117.20.210.52^ +||117.20.220.126^ ||117.20.236.14^ ||117.20.243.40^ +||117.20.247.150^ ||117.200.76.54^ -||117.26.110.103^ +||117.202.66.15^ +||117.202.69.113^ +||117.213.10.108^ +||117.213.15.72^ +||117.248.63.12^ ||117.63.113.146^ ||117.63.195.140^ ||117.63.53.15^ @@ -464,12 +453,11 @@ ||118.42.125.246^ ||118.43.180.33^ ||118.79.125.92^ -||118.79.218.157^ ||118.79.50.203^ ||118.79.58.82^ -||118.79.96.11^ ||118.83.79.43^ ||118.91.24.27^ +||118.91.41.135^ ||118.99.179.164^ ||118.99.183.235^ ||118.99.239.217^ @@ -480,7 +468,6 @@ ||119.147.213.57^ ||119.163.93.191^ ||119.164.18.235^ -||119.164.218.229^ ||119.165.107.93^ ||119.165.163.220^ ||119.165.174.63^ @@ -493,8 +480,6 @@ ||119.167.26.33^ ||119.177.147.38^ ||119.178.248.123^ -||119.179.157.219^ -||119.179.16.149^ ||119.179.170.212^ ||119.179.43.1^ ||119.179.75.8^ @@ -503,7 +488,6 @@ ||119.180.108.227^ ||119.180.108.79^ ||119.180.33.161^ -||119.180.94.80^ ||119.181.119.21^ ||119.181.124.203^ ||119.182.97.232^ @@ -523,12 +507,12 @@ ||119.251.105.221^ ||119.251.14.251^ ||119.56.131.155^ +||119.56.140.73^ ||119.56.143.46^ ||119.56.143.71^ ||119.56.144.75^ ||119.56.148.115^ ||119.56.155.57^ -||119.56.172.28^ ||119.56.175.41^ ||119.56.195.90^ ||119.56.206.43^ @@ -559,22 +543,17 @@ ||120.193.91.212^ ||120.193.91.215^ ||120.193.91.233^ -||120.209.121.243^ ||120.209.126.206^ ||120.209.126.240^ ||120.209.127.187^ ||120.209.99.127^ ||120.210.89.79^ ||120.43.33.202^ -||120.5.15.95^ ||120.50.66.60^ ||120.50.93.115^ -||120.6.141.142^ ||120.6.8.11^ ||120.7.75.99^ ||120.85.173.168^ -||120.85.174.3^ -||120.85.210.232^ ||121.100.114.164^ ||121.100.96.8^ ||121.121.44.222^ @@ -595,10 +574,8 @@ ||121.237.226.202^ ||121.239.15.74^ ||121.24.116.173^ -||121.25.101.86^ ||121.254.43.215^ ||121.254.76.17^ -||121.61.101.125^ ||121.61.98.151^ ||121.88.99.236^ ||122.100.150.204^ @@ -609,7 +586,6 @@ ||122.199.66.28^ ||122.199.72.23^ ||122.199.79.27^ -||122.199.83.86^ ||122.202.37.85^ ||122.202.41.23^ ||122.254.29.37^ @@ -626,28 +602,26 @@ ||123.128.133.91^ ||123.129.84.36^ ||123.130.208.52^ -||123.130.23.110^ ||123.130.27.19^ ||123.130.37.182^ -||123.130.61.210^ -||123.130.77.225^ ||123.131.186.250^ ||123.132.219.147^ ||123.133.125.77^ ||123.133.98.135^ ||123.134.14.130^ ||123.134.50.186^ -||123.14.120.130^ ||123.14.199.130^ +||123.14.248.210^ ||123.153.80.178^ ||123.154.116.116^ ||123.154.236.114^ ||123.154.94.1^ ||123.156.136.21^ +||123.159.68.119^ ||123.159.8.100^ ||123.183.121.60^ -||123.191.150.147^ ||123.191.164.92^ +||123.191.62.239^ ||123.192.101.163^ ||123.192.194.233^ ||123.193.149.235^ @@ -672,13 +646,10 @@ ||123.241.148.58^ ||123.241.184.124^ ||123.28.217.23^ -||123.5.189.116^ ||123.5.5.242^ -||123.8.184.82^ ||124.119.108.87^ ||124.129.221.150^ ||124.129.76.230^ -||124.130.110.167^ ||124.130.40.31^ ||124.131.104.82^ ||124.131.151.135^ @@ -691,7 +662,6 @@ ||124.153.136.175^ ||124.153.236.6^ ||124.160.126.238^ -||124.163.163.193^ ||124.163.65.64^ ||124.163.72.102^ ||124.165.123.7^ @@ -715,8 +685,6 @@ ||125.40.75.22^ ||125.41.215.9^ ||125.43.53.9^ -||125.45.63.67^ -||125.46.129.159^ ||125.79.200.104^ ||128.116.133.92^ ||130.255.159.133^ @@ -728,10 +696,12 @@ ||139.216.102.151^ ||139.227.46.137^ ||14.102.17.222^ +||14.102.97.204^ ||14.136.80.242^ ||14.138.8.51^ -||14.178.163.235^ +||14.160.34.50^ ||14.189.247.118^ +||14.241.227.216^ ||14.37.222.190^ ||14.45.127.110^ ||14.46.25.17^ @@ -758,23 +728,19 @@ ||153.101.47.145^ ||153.3.152.106^ ||153.34.135.92^ -||153.36.126.35^ ||155.138.134.44^ ||158.101.165.14^ ||158.174.213.128^ -||158.247.195.165^ ||158.51.125.115^ ||159.224.74.112^ ||162.194.28.60^ ||162.209.98.174^ ||163.53.206.228^ ||165.90.16.5^ -||168.205.223.254^ ||170.81.238.178^ ||171.113.36.216^ ||171.113.38.107^ ||171.121.255.10^ -||171.34.112.42^ ||171.34.114.181^ ||171.34.176.217^ ||171.34.179.178^ @@ -784,6 +750,7 @@ ||172.114.244.127^ ||172.245.5.185^ ||172.245.5.190^ +||172.245.79.106^ ||172.245.81.19^ ||172.93.194.114^ ||173.167.85.89^ @@ -810,7 +777,6 @@ ||175.169.13.182^ ||175.201.104.192^ ||175.208.230.8^ -||175.212.6.169^ ||175.42.46.118^ ||175.9.24.110^ ||175.9.90.89^ @@ -822,7 +788,6 @@ ||176.111.174.67^ ||176.113.161.104^ ||176.113.161.113^ -||176.113.161.138^ ||176.113.161.60^ ||176.113.161.65^ ||176.113.161.66^ @@ -836,7 +801,7 @@ ||176.123.7.127^ ||176.123.9.243^ ||176.124.7.225^ -||176.221.242.166^ +||176.221.188.251^ ||176.240.84.106^ ||177.11.92.78^ ||177.131.226.235^ @@ -846,35 +811,31 @@ ||178.124.182.187^ ||178.141.142.15^ ||178.150.174.65^ +||178.151.143.2^ ||178.165.122.141^ ||178.175.0.200^ ||178.175.1.137^ -||178.175.1.153^ ||178.175.1.179^ ||178.175.1.248^ ||178.175.1.249^ ||178.175.1.250^ ||178.175.1.44^ ||178.175.1.80^ +||178.175.100.151^ +||178.175.100.7^ ||178.175.101.110^ ||178.175.101.232^ -||178.175.102.133^ ||178.175.102.171^ ||178.175.102.67^ ||178.175.103.98^ -||178.175.104.145^ ||178.175.104.155^ ||178.175.104.69^ -||178.175.105.125^ ||178.175.105.95^ -||178.175.106.118^ ||178.175.106.193^ -||178.175.106.201^ ||178.175.107.0^ ||178.175.107.245^ ||178.175.107.83^ ||178.175.108.105^ -||178.175.108.149^ ||178.175.108.87^ ||178.175.109.129^ ||178.175.109.26^ @@ -886,23 +847,19 @@ ||178.175.111.206^ ||178.175.112.135^ ||178.175.112.139^ +||178.175.112.140^ ||178.175.112.147^ ||178.175.112.159^ ||178.175.112.46^ ||178.175.112.58^ -||178.175.113.27^ ||178.175.114.114^ -||178.175.114.63^ ||178.175.115.110^ ||178.175.115.209^ ||178.175.116.101^ ||178.175.116.138^ -||178.175.116.168^ -||178.175.116.90^ ||178.175.117.30^ ||178.175.118.112^ ||178.175.118.146^ -||178.175.118.210^ ||178.175.119.102^ ||178.175.119.114^ ||178.175.119.69^ @@ -923,18 +880,15 @@ ||178.175.123.26^ ||178.175.123.2^ ||178.175.123.30^ -||178.175.123.48^ ||178.175.123.91^ ||178.175.124.131^ ||178.175.124.155^ ||178.175.124.4^ -||178.175.124.79^ ||178.175.125.14^ ||178.175.125.160^ ||178.175.125.220^ ||178.175.125.88^ ||178.175.126.129^ -||178.175.126.153^ ||178.175.126.252^ ||178.175.126.46^ ||178.175.127.202^ @@ -944,7 +898,6 @@ ||178.175.13.254^ ||178.175.15.199^ ||178.175.15.215^ -||178.175.15.35^ ||178.175.16.108^ ||178.175.16.116^ ||178.175.16.251^ @@ -953,20 +906,17 @@ ||178.175.17.118^ ||178.175.17.61^ ||178.175.18.23^ +||178.175.18.37^ ||178.175.18.75^ ||178.175.19.163^ ||178.175.19.174^ ||178.175.19.91^ -||178.175.2.118^ -||178.175.2.123^ ||178.175.2.209^ ||178.175.2.5^ ||178.175.20.117^ ||178.175.20.70^ ||178.175.20.97^ ||178.175.21.149^ -||178.175.21.184^ -||178.175.21.238^ ||178.175.22.237^ ||178.175.23.144^ ||178.175.23.176^ @@ -978,7 +928,6 @@ ||178.175.25.56^ ||178.175.26.215^ ||178.175.27.114^ -||178.175.27.127^ ||178.175.27.171^ ||178.175.27.213^ ||178.175.27.32^ @@ -987,17 +936,16 @@ ||178.175.28.239^ ||178.175.28.47^ ||178.175.29.21^ -||178.175.29.2^ ||178.175.3.172^ ||178.175.3.214^ ||178.175.30.133^ ||178.175.30.151^ ||178.175.30.213^ -||178.175.31.251^ ||178.175.31.73^ ||178.175.32.146^ ||178.175.32.220^ ||178.175.32.89^ +||178.175.33.162^ ||178.175.33.7^ ||178.175.34.217^ ||178.175.34.247^ @@ -1014,11 +962,12 @@ ||178.175.4.144^ ||178.175.4.72^ ||178.175.40.136^ -||178.175.40.166^ ||178.175.40.228^ ||178.175.42.101^ ||178.175.42.6^ ||178.175.43.121^ +||178.175.43.223^ +||178.175.43.229^ ||178.175.43.238^ ||178.175.43.244^ ||178.175.44.0^ @@ -1031,13 +980,11 @@ ||178.175.45.26^ ||178.175.46.129^ ||178.175.46.137^ -||178.175.46.243^ ||178.175.46.41^ ||178.175.46.42^ ||178.175.46.8^ ||178.175.47.143^ ||178.175.48.51^ -||178.175.49.12^ ||178.175.5.57^ ||178.175.50.10^ ||178.175.50.177^ @@ -1056,10 +1003,8 @@ ||178.175.56.82^ ||178.175.56.87^ ||178.175.57.134^ -||178.175.57.179^ ||178.175.58.183^ ||178.175.58.79^ -||178.175.59.131^ ||178.175.59.33^ ||178.175.6.115^ ||178.175.6.140^ @@ -1071,15 +1016,12 @@ ||178.175.60.209^ ||178.175.60.212^ ||178.175.60.221^ -||178.175.61.235^ -||178.175.62.232^ ||178.175.62.70^ ||178.175.62.81^ ||178.175.63.21^ ||178.175.64.156^ ||178.175.66.186^ ||178.175.66.192^ -||178.175.66.211^ ||178.175.68.116^ ||178.175.68.123^ ||178.175.68.209^ @@ -1088,60 +1030,51 @@ ||178.175.69.153^ ||178.175.69.67^ ||178.175.7.105^ -||178.175.7.107^ ||178.175.7.14^ -||178.175.7.21^ ||178.175.7.35^ ||178.175.7.60^ ||178.175.7.79^ -||178.175.70.212^ ||178.175.70.218^ +||178.175.71.179^ ||178.175.72.222^ ||178.175.72.65^ -||178.175.73.42^ ||178.175.75.181^ ||178.175.75.244^ -||178.175.77.248^ -||178.175.77.46^ ||178.175.77.47^ ||178.175.78.169^ +||178.175.78.242^ ||178.175.78.2^ -||178.175.8.181^ ||178.175.80.89^ -||178.175.81.176^ ||178.175.81.226^ -||178.175.81.235^ ||178.175.81.31^ +||178.175.83.247^ ||178.175.83.2^ ||178.175.84.215^ -||178.175.84.61^ ||178.175.85.23^ ||178.175.85.53^ ||178.175.86.59^ ||178.175.87.146^ ||178.175.87.42^ ||178.175.87.91^ -||178.175.88.166^ ||178.175.88.4^ +||178.175.89.121^ ||178.175.89.217^ ||178.175.89.6^ ||178.175.9.179^ ||178.175.9.198^ ||178.175.9.4^ -||178.175.90.81^ +||178.175.90.4^ ||178.175.92.102^ ||178.175.92.1^ ||178.175.92.92^ ||178.175.93.143^ -||178.175.94.182^ ||178.175.94.27^ ||178.175.94.32^ ||178.175.94.40^ ||178.175.94.61^ ||178.175.95.120^ -||178.175.96.218^ ||178.175.96.251^ -||178.175.97.14^ +||178.175.97.113^ ||178.175.98.83^ ||178.175.99.120^ ||178.175.99.130^ @@ -1154,7 +1087,6 @@ ||178.222.252.130^ ||178.34.183.30^ ||178.48.235.59^ -||178.72.91.172^ ||178.95.136.35^ ||179.159.58.134^ ||179.60.84.7^ @@ -1163,7 +1095,6 @@ ||180.116.203.220^ ||180.122.13.227^ ||180.123.208.250^ -||180.125.44.194^ ||180.157.66.204^ ||180.175.236.209^ ||180.176.105.41^ @@ -1199,30 +1130,20 @@ ||182.116.61.252^ ||182.116.99.150^ ||182.117.43.185^ -||182.117.43.82^ ||182.119.120.8^ ||182.119.164.128^ -||182.119.200.62^ ||182.119.202.130^ ||182.120.16.22^ ||182.120.16.46^ -||182.121.127.106^ -||182.123.205.157^ -||182.123.211.239^ -||182.124.138.54^ -||182.126.121.211^ +||182.121.26.37^ ||182.127.152.3^ ||182.160.98.250^ ||182.233.0.252^ ||182.235.252.31^ ||182.53.197.62^ -||183.105.104.83^ ||183.105.225.154^ ||183.109.169.45^ ||183.128.152.115^ -||183.144.9.97^ -||183.185.112.19^ -||183.83.18.203^ ||183.83.29.191^ ||183.92.207.147^ ||184.164.185.41^ @@ -1249,7 +1170,6 @@ ||185.68.230.207^ ||185.81.157.186^ ||185.82.217.185^ -||185.82.217.213^ ||185.82.219.160^ ||185.82.219.161^ ||185.82.219.219^ @@ -1268,7 +1188,6 @@ ||187.12.10.98^ ||187.188.124.229^ ||187.212.200.162^ -||187.85.244.145^ ||188.10.21.14^ ||188.10.231.246^ ||188.113.81.17^ @@ -1277,6 +1196,8 @@ ||188.143.220.152^ ||188.152.41.141^ ||188.169.178.50^ +||188.169.179.127^ +||188.169.199.59^ ||188.242.242.144^ ||188.81.100.83^ ||188.83.202.25^ @@ -1316,7 +1237,6 @@ ||192.227.185.106^ ||192.227.209.27^ ||192.227.220.55^ -||192.227.223.96^ ||192.227.228.67^ ||192.227.230.74^ ||192.3.152.166^ @@ -1350,7 +1270,6 @@ ||1am.co.nz^ ||2.229.89.119^ ||2.239.22.188^ -||2.249.161.188^ ||2.37.149.230^ ||2.37.203.65^ ||2.45.4.24^ @@ -1359,7 +1278,6 @@ ||2.57.122.107^ ||2.83.152.16^ ||20.185.42.197^ -||200.104.150.167^ ||200.105.167.98^ ||200.111.189.70^ ||200.194.4.24^ @@ -1370,11 +1288,10 @@ ||201.184.163.170^ ||201.187.102.73^ ||201.200.254.86^ +||201.203.221.20^ ||201.203.27.37^ -||201.205.12.170^ ||202.107.233.41^ ||202.150.176.100^ -||202.166.217.54^ ||202.175.103.10^ ||202.29.95.12^ ||202.4.124.58^ @@ -1387,7 +1304,6 @@ ||203.229.21.56^ ||203.236.190.28^ ||203.238.86.202^ -||203.243.142.132^ ||203.70.166.107^ ||203.77.80.159^ ||203.80.119.166^ @@ -1397,7 +1313,6 @@ ||204.195.116.171^ ||205.185.115.74^ ||205.185.116.94^ -||205.185.123.217^ ||206.248.137.132^ ||206.47.41.166^ ||207.180.228.101^ @@ -1407,8 +1322,8 @@ ||209.141.39.50^ ||209.141.40.190^ ||209.141.40.31^ -||209.141.46.87^ ||210.124.149.19^ +||210.180.17.140^ ||210.216.152.122^ ||210.216.153.142^ ||210.57.234.93^ @@ -1419,7 +1334,6 @@ ||211.116.220.37^ ||211.187.132.204^ ||211.187.75.220^ -||211.200.160.239^ ||211.204.215.157^ ||211.210.66.179^ ||211.210.93.93^ @@ -1437,31 +1351,31 @@ ||212.46.197.114^ ||212.56.197.230^ ||212.8.251.211^ +||212.8.251.227^ ||213.123.206.197^ ||213.135.178.253^ ||213.14.173.117^ ||213.149.182.113^ ||213.149.190.193^ -||213.163.104.12^ ||213.163.104.99^ ||213.163.113.135^ ||213.163.113.20^ ||213.163.113.237^ ||213.163.113.6^ ||213.163.114.165^ +||213.163.114.191^ ||213.163.115.105^ ||213.163.115.11^ ||213.163.115.15^ ||213.163.115.30^ ||213.163.115.71^ -||213.163.116.192^ ||213.163.117.151^ +||213.163.118.10^ ||213.163.118.238^ ||213.163.118.65^ ||213.163.119.236^ -||213.163.126.175^ +||213.163.126.145^ ||213.163.126.7^ -||213.163.127.107^ ||213.163.127.46^ ||213.189.178.163^ ||213.240.218.15^ @@ -1476,32 +1390,26 @@ ||216.183.54.169^ ||216.36.12.98^ ||217.11.75.162^ +||217.127.133.214^ ||218.12.181.110^ ||218.2.40.34^ ||218.234.165.18^ ||218.238.246.3^ -||218.28.160.174^ ||218.35.207.119^ ||218.35.227.133^ ||218.35.68.35^ ||218.35.81.81^ ||218.56.93.129^ -||218.58.92.253^ ||218.59.116.203^ -||218.72.207.116^ ||218.79.103.159^ ||218.93.102.63^ ||218.93.102.75^ ||219.155.102.14^ -||219.155.11.207^ -||219.155.12.85^ -||219.155.26.190^ ||219.155.29.165^ ||219.156.186.18^ ||219.157.139.165^ ||219.157.150.91^ ||219.157.214.235^ -||219.157.50.106^ ||219.241.6.180^ ||219.68.1.148^ ||219.68.1.84^ @@ -1510,19 +1418,17 @@ ||219.68.245.63^ ||219.68.5.140^ ||219.69.71.186^ +||219.70.238.66^ ||219.80.217.209^ ||219.85.145.194^ ||21robo.com^ ||220.118.168.155^ ||220.126.237.74^ ||220.200.22.163^ -||220.247.91.17^ ||220.71.239.115^ -||220.90.159.188^ ||221.1.144.183^ ||221.124.78.15^ -||221.15.113.234^ -||221.157.191.178^ +||221.15.125.69^ ||221.160.136.213^ ||221.202.232.230^ ||221.214.130.147^ @@ -1544,16 +1450,15 @@ ||222.119.65.145^ ||222.132.125.138^ ||222.133.103.120^ -||222.135.67.115^ ||222.135.9.5^ ||222.137.148.192^ ||222.137.211.78^ ||222.138.17.132^ ||222.138.237.155^ ||222.140.17.245^ -||222.162.187.43^ ||222.179.215.189^ ||222.185.116.233^ +||222.186.20.19^ ||222.187.9.178^ ||222.211.72.66^ ||222.236.85.220^ @@ -1604,6 +1509,7 @@ ||27.105.106.201^ ||27.105.152.107^ ||27.116.84.57^ +||27.14.211.219^ ||27.14.81.201^ ||27.141.218.17^ ||27.147.29.52^ @@ -1647,8 +1553,6 @@ ||27.207.155.31^ ||27.207.170.203^ ||27.208.119.27^ -||27.208.152.10^ -||27.208.160.177^ ||27.208.164.18^ ||27.208.237.105^ ||27.208.247.130^ @@ -1658,13 +1562,13 @@ ||27.209.208.122^ ||27.209.231.15^ ||27.210.107.125^ -||27.210.172.245^ ||27.210.234.28^ ||27.210.236.134^ +||27.210.32.122^ ||27.210.44.19^ ||27.210.63.243^ ||27.213.104.201^ -||27.213.109.58^ +||27.213.109.105^ ||27.213.175.208^ ||27.213.255.202^ ||27.213.66.112^ @@ -1674,9 +1578,9 @@ ||27.215.190.172^ ||27.215.212.209^ ||27.215.253.149^ -||27.215.34.242^ ||27.215.71.243^ ||27.215.98.242^ +||27.216.117.54^ ||27.216.128.156^ ||27.216.131.66^ ||27.216.144.66^ @@ -1698,17 +1602,13 @@ ||27.220.85.168^ ||27.221.239.223^ ||27.222.241.223^ -||27.222.249.210^ ||27.222.76.80^ ||27.223.242.164^ ||27.24.28.134^ ||27.35.129.198^ ||27.35.154.13^ -||27.35.16.145^ -||27.35.2.30^ ||27.35.212.124^ ||27.35.58.5^ -||27.41.237.129^ ||27.43.117.98^ ||31.0.98.131^ ||31.11.51.57^ @@ -1735,18 +1635,19 @@ ||32.208.157.193^ ||32792.prolocksmithwinterpark.com^ ||35.184.169.169^ -||36.107.209.10^ ||36.108.231.218^ ||36.248.228.64^ +||36.248.83.98^ ||36.250.203.246^ ||36.251.157.225^ ||36.251.18.18^ ||36.251.51.244^ ||36.255.90.219^ +||36.33.128.58^ ||36.33.160.167^ ||36.34.150.236^ ||36.66.105.159^ -||36.66.111.203^ +||36.66.133.125^ ||36.66.139.36^ ||36.89.18.133^ ||360.lcy2zzx.pw^ @@ -1816,7 +1717,6 @@ ||39.81.70.88^ ||39.83.94.11^ ||39.84.115.152^ -||39.85.54.191^ ||39.85.54.4^ ||39.86.129.233^ ||39.86.170.209^ @@ -1827,10 +1727,10 @@ ||39.88.155.96^ ||39.88.233.131^ ||39.88.67.238^ +||39.88.72.9^ ||39.89.108.109^ ||39.89.145.11^ ||39.89.146.198^ -||39.89.146.36^ ||39.89.63.23^ ||39.90.86.212^ ||40.88.2.151^ @@ -1841,14 +1741,15 @@ ||41.219.185.171^ ||41.226.60.115^ ||41.72.203.82^ -||41.86.18.169^ -||41.86.21.23^ +||41.86.18.133^ ||41.86.21.27^ -||41.86.21.38^ +||41.86.5.197^ ||42.202.101.199^ +||42.228.39.211^ ||42.228.43.161^ ||42.228.65.104^ ||42.230.82.176^ +||42.232.81.179^ ||42.235.180.147^ ||42.239.26.122^ ||42.56.15.227^ @@ -1862,7 +1763,9 @@ ||45.133.1.242^ ||45.133.203.192^ ||45.135.134.228^ +||45.14.149.182^ ||45.14.149.204^ +||45.141.84.182^ ||45.141.84.184^ ||45.144.225.118^ ||45.144.225.135^ @@ -1888,16 +1791,12 @@ ||45.51.104.59^ ||45.6.24.251^ ||45.81.235.31^ -||45.85.90.131^ -||45.85.90.179^ ||45.85.90.203^ ||45.9.148.37^ ||45.92.108.125^ -||45.95.169.153^ ||46.117.42.29^ ||46.172.75.231^ ||46.182.173.246^ -||46.182.173.247^ ||46.20.63.218^ ||46.214.27.4^ ||46.24.130.254^ @@ -1915,6 +1814,7 @@ ||47.16.131.51^ ||47.21.202.98^ ||47.46.231.38^ +||49.119.187.230^ ||49.142.162.113^ ||49.142.87.36^ ||49.143.43.93^ @@ -1929,7 +1829,6 @@ ||49.68.221.252^ ||5.188.62.111^ ||5.2.70.50^ -||5.42.37.74^ ||5.53.146.179^ ||5.79.75.210^ ||5.95.226.154^ @@ -1937,7 +1836,6 @@ ||50.115.174.106^ ||50.121.91.255^ ||50.252.47.29^ -||51.222.56.159^ ||54.36.114.136^ ||54.36.180.122^ ||58.114.246.26^ @@ -1952,16 +1850,15 @@ ||58.218.67.253^ ||58.22.212.107^ ||58.226.129.29^ -||58.229.194.122^ ||58.230.89.42^ ||58.238.42.192^ ||58.240.147.97^ ||58.241.78.55^ -||58.243.123.212^ ||58.243.126.133^ ||58.243.208.225^ -||58.248.118.64^ -||58.249.80.181^ +||58.248.142.227^ +||58.249.79.174^ +||58.249.84.131^ ||58.48.154.143^ ||58.72.165.153^ ||58.72.165.39^ @@ -1970,12 +1867,14 @@ ||59.0.211.161^ ||59.102.168.189^ ||59.151.202.3^ -||59.151.207.150^ ||59.151.214.4^ ||59.151.237.51^ ||59.151.246.125^ ||59.23.114.97^ ||59.58.117.226^ +||59.93.18.144^ +||59.96.37.124^ +||59.97.169.237^ ||60.10.91.242^ ||60.13.61.12^ ||60.164.130.220^ @@ -2000,9 +1899,7 @@ ||60.217.177.196^ ||60.217.86.208^ ||60.223.84.102^ -||60.25.109.240^ ||60.253.15.104^ -||60.253.39.88^ ||60.253.4.72^ ||60.253.51.127^ ||60.253.60.174^ @@ -2012,25 +1909,21 @@ ||60.7.8.43^ ||60.7.99.254^ ||61.164.96.98^ -||61.179.171.60^ ||61.179.91.194^ ||61.247.224.66^ ||61.253.94.230^ -||61.3.149.112^ ||61.41.230.161^ ||61.47.220.169^ ||61.52.103.217^ ||61.52.199.47^ -||61.52.207.10^ ||61.52.30.172^ ||61.52.9.166^ -||61.52.9.62^ ||61.52.99.161^ -||61.53.102.137^ ||61.53.117.237^ -||61.53.220.0^ +||61.53.89.220^ ||61.54.103.56^ ||61.54.64.63^ +||61.54.69.77^ ||61.56.180.67^ ||61.56.181.7^ ||61.57.96.116^ @@ -2131,7 +2024,6 @@ ||74.64.139.223^ ||74.75.165.81^ ||75.127.141.52^ -||75.82.36.220^ ||75.83.102.27^ ||75.99.213.61^ ||76.170.11.82^ @@ -2143,7 +2035,6 @@ ||76.95.12.137^ ||77.111.182.31^ ||77.237.25.210^ -||77.53.144.46^ ||77.71.50.153^ ||77.71.52.220^ ||77.89.203.238^ @@ -2165,6 +2056,7 @@ ||79.130.253.13^ ||79.147.123.48^ ||79.175.42.244^ +||79.21.84.63^ ||79.7.170.58^ ||79.79.58.94^ ||79.8.70.162^ @@ -2178,6 +2070,7 @@ ||81.165.44.109^ ||81.191.40.58^ ||81.213.141.184^ +||81.215.199.29^ ||81.218.187.113^ ||81.218.195.216^ ||81.237.128.200^ @@ -2245,7 +2138,7 @@ ||86.35.43.220^ ||87.172.19.130^ ||87.61.89.40^ -||87du.vip^ +||88.119.171.253^ ||88.2.208.71^ ||88.2.219.179^ ||88.225.222.128^ @@ -2279,6 +2172,7 @@ ||92.114.191.82^ ||92.241.78.114^ ||92.27.246.202^ +||92.54.237.237^ ||92.83.62.139^ ||92.85.18.138^ ||93.159.169.190^ @@ -2306,7 +2200,6 @@ ||95.60.146.134^ ||95.66.196.63^ ||95.9.120.40^ -||95.9.81.85^ ||96.239.73.246^ ||96.47.147.169^ ||97.68.140.254^ @@ -2378,6 +2271,7 @@ ||anantam.net.in^ ||andreelapeyre.com^ ||andremaraisbeleggings.co.za^ +||andreonemaia.com^ ||andres.ac.ug^ ||andres.ug^ ||andreshconcejal.solucioneslink.com^ @@ -2387,7 +2281,6 @@ ||anhung1102.vn^ ||anurontv.com^ ||anysbergbiltong.co.za^ -||apartamentoscitta.com^ ||api-ms.cobainaja.id^ ||api.cstdevs.com^ ||api.quocbao.biz^ @@ -2410,15 +2303,17 @@ ||attach.66rpg.com^ ||atteuqpotentialunlimited.com^ ||augustair.com^ +||aulist.com^ +||automaticrefreshments.com^ ||avadhanagames.com^ ||ayahuascasp.com.br^ ||ayamallah.com^ +||aycconsultoriaempresarial.com^ ||azmeasurement.com^ ||b2b.toptanakaryakit.com.tr^ ||backgrounds.pk^ ||badeggdesign.com^ ||balealgodon.mx^ -||ballina.andrewmaughan.com^ ||bangkok-orchids.com^ ||bangladeshunbound.com^ ||bary.sz4h.com^ @@ -2429,6 +2324,7 @@ ||bcmt.elin.co.za^ ||bcrg.co.za^ ||bdnextrend.xyz^ +||beanx88.xyz^ ||bearcatpumps.com.cn^ ||beautincollagen.rs^ ||bekape.co.id^ @@ -2436,6 +2332,7 @@ ||bespokeweddings.ie^ ||bestcarenepal.com^ ||betone.co.kr^ +||betycopaints.com^ ||beveragesmiami.solucioneslink.com^ ||bhavaniengineering.com^ ||bigmikesupplies.co.za^ @@ -2464,6 +2361,7 @@ ||bounces.mi-fs.com^ ||boutiqueofferte.com^ ||bpo.correct.go.th^ +||bradleyinstitute.co.za^ ||brandtrust.com.pk^ ||braunfinancial.com.au^ ||brendanquine.com^ @@ -2514,6 +2412,7 @@ ||childselect.com^ ||chinhdropfile.myvnc.com^ ||chinhdropfile80.myvnc.com^ +||chipmania.it^ ||cible-energy.com^ ||cifeer.net^ ||cirugiadenarizbucaramanga.com^ @@ -2527,10 +2426,9 @@ ||cm-arquitetos.com^ ||codsambal.com^ ||colempaques.info^ -||colinde.pricesne.com^ ||colorpak.pl^ +||columbia.aula-web.net^ ||community.reimclub.com^ -||comosairdoburaco.com.br^ ||competancy.indigoconsult.net^ ||conceptimagine.ro^ ||config.cqhbkjzx.com^ @@ -2546,7 +2444,6 @@ ||cpanel.shivay.net^ ||cr-sq.com^ ||craftech.nxtnet.ga^ -||crearechile.cl^ ||creationskateboards.com^ ||crecerco.com^ ||crittersbythebay.com^ @@ -2556,7 +2453,6 @@ ||crscorretordeimoveis.com.br^ ||cse-engineer.com^ ||csnserver.com^ -||ctracknxt.in^ ||cubescargoexpress.com^ ||curasoles.co.za^ ||currantmedia.com^ @@ -2575,7 +2471,6 @@ ||data.over-blog-kiwi.com^ ||datapolish.com^ ||dating.khokhas.co.za^ -||datsom.vn^ ||davethompson.me.uk^ ||davidmcguinness.info^ ||dayspringdaisies.com^ @@ -2599,7 +2494,6 @@ ||detorre.es^ ||dev.sebpo.net^ ||dev.watch-store.eu^ -||dezcom.com^ ||dfcf.91756.cn^ ||dfsfcsfcdsfsdvcfsvcscv.com^ ||diamantenegro.mi-fs.com^ @@ -2614,6 +2508,7 @@ ||dl.packetstormsecurity.net^ ||dl.rina-roleplay.com^ ||dnn.alibuf.com^ +||dns.alibuf.com^ ||dns.cyberium.cc^ ||dockerupdate.anondns.net^ ||docman.orientalservices.in^ @@ -2630,6 +2525,8 @@ ||dosman.pl^ ||dovberger.com^ ||down.pcclear.com^ +||down.postch-de.top^ +||down.postch-dl.top^ ||down.udashi.com^ ||down.webbora.com^ ||down1.arpun.com^ @@ -2689,14 +2586,13 @@ ||f1sol.com^ ||fahrzeugdrive.com^ ||familydentist.site^ -||faveraprojects.com^ ||fc.co.mz^ ||felicienne.nl^ ||files.martellexpress.us^ ||filmotainment.com^ ||final.makkahkmcc.com^ ||fineartgallerym.com^ -||fisconline.casa^ +||fisconline.bar^ ||fix-america-now.org^ ||fixauto.illumetechnology.com^ ||fixturegovernment.com^ @@ -2711,7 +2607,6 @@ ||footweardirect.elin.co.za^ ||forum.mdb.nu^ ||fotoobjetivo.com^ -||foundationrepairhoustontx.net^ ||foxeps.com.br^ ||fraud.bpcbankingtech.com^ ||freecnetdownload.com^ @@ -2720,7 +2615,6 @@ ||fullelectronica.com.ar^ ||funletters.net^ ||fusionfiresolutions.com^ -||futbolpr.com^ ||futuregraphics.com.ar^ ||g.pinmonkey.xyz^ ||gametwogame.com^ @@ -2737,6 +2631,7 @@ ||ghislain.dartois.pagesperso-orange.fr^ ||giadungg7.com^ ||giddos.ga^ +||giteletropical.com^ ||glowinmedia.co.ke^ ||gmsebpl.com^ ||gmtransformationacademy.com^ @@ -2749,6 +2644,7 @@ ||goldcoastoffice365.com^ ||golden-memories-funerals.yourpageserver.com^ ||goldenasiacapital.com^ +||goldmen.in^ ||gorecycle.fahadjutt.com^ ||gpotecnosystems.com^ ||gracejukes.com^ @@ -2777,13 +2673,12 @@ ||highlandroadcoc.com^ ||highlandslasvegas.atakdev.com^ ||hindi.factsriver.com^ -||hiptool.net^ ||hitpe.com^ ||hitstation.nl^ +||hlmd.in^ ||hmpmall.co.kr^ ||hoagietesting10.com^ ||hoayeuthuong-my.sharepoint.com^ -||holmesservices.mobiledevsite.co^ ||homefindersolutions.com^ ||hongluosi.com^ ||hookedupboatclub.com^ @@ -2794,7 +2689,6 @@ ||hr2019.vrcom7.com^ ||hrnautica.com.br^ ||hseda.com^ -||hsmwebapp.com^ ||htownbars.com^ ||hubtech.co.za^ ||huellacero.cl^ @@ -2834,16 +2728,19 @@ ||ipmes.ma^ ||iremart.es^ ||iris101.co.uk^ +||isaac.mikhailmotoringschool.com^ ||iscamenabe.com^ ||isiphephelocon.co.za^ ||iso-dubai.net^ ||israrulhaq.me^ +||isrorg.com^ ||isso.ps^ ||ist-security.com^ ||it123.ru^ ||italiandirezione.casa^ ||itc-demo.softgig.co.ke^ ||itelsys.ma^ +||itmotasaciones.com^ ||jacktech.jackindia.com^ ||jaishritours.com^ ||jamiekaylive.com^ @@ -2857,6 +2754,7 @@ ||jhayesconsulting.com^ ||jiaoyuzixun.cn^ ||jing-da.com.tw^ +||jmtc.91756.cn^ ||jnanbharati.com^ ||jobs.thebeessolution.com^ ||joelbonissilver.com^ @@ -2867,6 +2765,7 @@ ||jupiter.toxsl.in^ ||justinscott.com.au^ ||kadigital.co.uk^ +||kaizenjanitorial.com^ ||kalawatihomes.com^ ||kalogirosfinance.com^ ||kaptaanchapal.com^ @@ -2928,14 +2827,16 @@ ||lp.definerisco.com^ ||lp.difusodesign.com^ ||lp.quama.pe^ -||ltc.typoten.com^ +||luckybrownie.com^ ||luminouspneuma.com^ ||luxomodels.com^ ||m-technics.kz^ ||m.estudiomoros.com.ar^ ||m.mobilelocalsales.com^ +||m.softsharks.com^ ||madicon.co.za^ ||magianegramagiablancayamarres.com^ +||maharaniworld.com^ ||mail.bs-eiendomme.co.za^ ||mail.golimoapp.com^ ||mail.jeffsono.org^ @@ -2961,7 +2862,6 @@ ||maxiquim.cl^ ||maxoprint.co.uk^ ||maxtox.com.pk^ -||maybethescobar.com^ ||mbgrm.com^ ||mbjtimes.com^ ||mbsolutions.ge^ @@ -2992,11 +2892,12 @@ ||michimal2.000webhostapp.com^ ||microblading.mirliandias.com.br^ ||microcomm-group.com^ +||mikhailmotoringschool.com^ +||mills-skyla30ec.com^ ||mingguanwms.com^ ||minuevavida.org^ ||mirror.mypage.sk^ ||misterson.com^ -||mixr.at^ ||mkontakt.az^ ||mktf.mx^ ||mmdx.com^ @@ -3033,6 +2934,7 @@ ||nec-i.com^ ||nedkellymyanmar.com^ ||nelitrianggraeni.000webhostapp.com^ +||nellaimasthanbiryani.com^ ||nerve.untergrund.net^ ||nettube.com.br^ ||networkwheels.co.za^ @@ -3057,7 +2959,6 @@ ||nobius.org^ ||nocalnoodle.elin.co.za^ ||nomadicbees.com^ -||nonnarina.ax^ ||notamuzikaletleri.com^ ||ns1.the-widyantos.com^ ||nsb.org.uk^ @@ -3077,12 +2978,15 @@ ||omega.az^ ||oms.pappai.com^ ||omscoc.pappai.com^ +||onedigitalcard.granvizionnecorp.com^ ||onedrive.listifyapp.co^ ||online.creedglobal.in^ ||onlinestatis.bar^ +||open.rawntech.com^ ||open.warehousesaas.co.uk^ ||opentoronto.org^ ||opolis.io^ +||opticaoptigral.cl^ ||optimus.com.sg^ ||order.bizpeed.com^ ||orientgatewayltd.com^ @@ -3120,6 +3024,7 @@ ||pd.oceaniarp.net^ ||pemdodo.com^ ||perfumeriamontes.es^ +||periodiche.bar^ ||perpus.onlineman7-jombang.sch.id^ ||perpustekim.untirta.ac.id^ ||pestoclean.co.uk^ @@ -3139,6 +3044,7 @@ ||pointactionsg.com^ ||pokojewewladyslawowie.pl^ ||pole.com.vc^ +||ponchokhana.com^ ||pool.phxdir.com^ ||pooltablemoversdenver.net^ ||portal.premiumpunch.com^ @@ -3149,6 +3055,7 @@ ||prestigehomeautomation.net^ ||preview2.behalen.com^ ||prishaartcreations.com^ +||prismaxis.com^ ||production.sparshims.com^ ||programaoperadoronline.com.br^ ||project.exquitec.com^ @@ -3200,7 +3107,6 @@ ||resuco.net^ ||rezkabum.ru^ ||rhema.com.sg^ -||richancyber.info^ ||richmondminerals.co.zm^ ||rinaefoundation.org.za^ ||rinkaisystem-ht.com^ @@ -3209,7 +3115,6 @@ ||rkverify.securestudies.com^ ||robertmcardle.com^ ||robertsinclair.net^ -||romanianpoints.com^ ||ronnietucker.co.uk^ ||roomsvc.servegate.kr^ ||roshnijewellery.com^ @@ -3219,7 +3124,6 @@ ||ruisgood.ru^ ||ruwadalkuwait.com^ ||rydchile.cl^ -||s.51shijuan.com^ ||s.thechinesemuslim.com^ ||sac2.11xii.com^ ||sacredscentsonline.com^ @@ -3253,7 +3157,9 @@ ||sericaasia.com^ ||servicemhkd.myvnc.com^ ||servicemhkd80.myvnc.com^ +||serviciovirtual.com.ar^ ||sexologistpakistan.net^ +||seyranikenger.com.tr^ ||sgb.ac.ke^ ||sgessy.com.br^ ||shaheentbfoundation.com^ @@ -3304,6 +3210,7 @@ ||special-key.cf^ ||spent.com.pl^ ||spetsesyachtcharter.gr^ +||spiritualroot.org^ ||spititourism.com^ ||spittinfire.com^ ||sports-net.de^ @@ -3323,7 +3230,7 @@ ||stlukesohag.com^ ||store.ericalgarin.com^ ||stott-thompson.co.uk^ -||streetdemo.yourpageserver.com^ +||stratexec.co.za^ ||suboldesign.com^ ||sumerians.org^ ||sunaryem.com.tr^ @@ -3371,6 +3278,7 @@ ||test.typoten.com^ ||test.wanepghana.org^ ||test1.asistencia247.com^ +||test1.milenial.id^ ||test1.tenplusone.my^ ||test2.basis-web.com^ ||test2.marrenconstruction.ie^ @@ -3395,7 +3303,7 @@ ||theprofinn.com^ ||thesummitpc.net^ ||theurbantutors.com^ -||thientu.net^ +||thirdstringcalifornia.com^ ||thosewebbs.com^ ||thriveink.com^ ||tianangdep.com^ @@ -3405,7 +3313,6 @@ ||timegonebuy.com^ ||tksb.net^ ||tlcc.com.gt^ -||tntmedia.gr^ ||todoapp.cstdevs.com^ ||todocontodo.com.mx^ ||tonydong.com^ @@ -3442,6 +3349,7 @@ ||umwelt-kirchhof.de^ ||unicorpbrunei.com^ ||uniengrisb.com^ +||unisoftcc.com^ ||unyazitelecom.com^ ||upcbpta.com^ ||urbantrapfest.cl^ @@ -3456,7 +3364,9 @@ ||vcah.co.uk^ ||vectarts.com^ ||vegadelcasero.cl^ +||velma-harber30ku.com^ ||vendas.lidiacarmeli.com.br^ +||versualstudio.com^ ||veterinariadrpopui.com^ ||vfocus.net^ ||vienen.gblix.srv.br^ @@ -3483,6 +3393,7 @@ ||w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu^ ||wanepliberia.org^ ||wanepniger.org^ +||weareactum.com^ ||web.eng.ubu.ac.th^ ||web.geetle.ga^ ||web.geomegasoft.net^ @@ -3510,6 +3421,7 @@ ||wonderhawaii.com^ ||woodsytech.com^ ||wordpress.saleensuporte.com.br^ +||workingsolutionsrome.org^ ||wozata.000webhostapp.com^ ||wp.readhere.in^ ||wpdemo.101clients.com.au^ @@ -3531,7 +3443,6 @@ ||yourclub1.com^ ||yourtopdog.com.au^ ||youtubetrainingacademy.com^ -||yp.hnggzyjy.cn^ ||yskadvisors.com^ ||yummyyogaudaipur.com^ ||yzkzixun.com^ diff --git a/urlhaus-filter-agh.txt b/urlhaus-filter-agh.txt index fe4041e0..f28dafde 100644 --- a/urlhaus-filter-agh.txt +++ b/urlhaus-filter-agh.txt @@ -1,5 +1,5 @@ ! Title: Malicious URL Blocklist (AdGuard Home) -! Updated: Sat, 03 Apr 2021 00:13:46 UTC +! Updated: Sat, 03 Apr 2021 12:12:28 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -2024,6 +2024,7 @@ ||101.109.78.164^ ||101.109.85.37^ ||101.109.85.40^ +||101.126.102.31^ ||101.126.155.223^ ||101.126.87.66^ ||101.128.72.166^ @@ -3770,6 +3771,7 @@ ||103.217.123.134^ ||103.217.123.137^ ||103.217.123.142^ +||103.217.123.143^ ||103.217.123.145^ ||103.217.123.147^ ||103.217.123.14^ @@ -4420,6 +4422,7 @@ ||103.41.25.189^ ||103.41.25.201^ ||103.41.25.203^ +||103.41.25.206^ ||103.41.25.212^ ||103.41.25.21^ ||103.41.25.233^ @@ -12058,6 +12061,7 @@ ||111.92.80.176^ ||111.92.80.182^ ||111.92.80.183^ +||111.92.80.192^ ||111.92.80.195^ ||111.92.80.196^ ||111.92.80.201^ @@ -20047,6 +20051,7 @@ ||112.80.215.101^ ||112.80.215.227^ ||112.80.215.229^ +||112.80.218.56^ ||112.80.236.136^ ||112.80.236.158^ ||112.80.236.45^ @@ -50018,6 +50023,7 @@ ||115.56.130.27^ ||115.56.130.30^ ||115.56.130.32^ +||115.56.130.33^ ||115.56.130.52^ ||115.56.130.55^ ||115.56.130.5^ @@ -93129,6 +93135,7 @@ ||116.68.97.187^ ||116.68.97.192^ ||116.68.97.193^ +||116.68.97.199^ ||116.68.97.1^ ||116.68.97.204^ ||116.68.97.212^ @@ -116911,6 +116918,7 @@ ||117.202.69.110^ ||117.202.69.111^ ||117.202.69.112^ +||117.202.69.113^ ||117.202.69.114^ ||117.202.69.115^ ||117.202.69.116^ @@ -118553,6 +118561,7 @@ ||117.208.135.215^ ||117.208.135.217^ ||117.208.135.218^ +||117.208.135.220^ ||117.208.135.225^ ||117.208.135.227^ ||117.208.135.229^ @@ -119413,6 +119422,7 @@ ||117.212.52.160^ ||117.212.54.132^ ||117.212.55.67^ +||117.213.10.108^ ||117.213.10.115^ ||117.213.10.125^ ||117.213.10.140^ @@ -119467,6 +119477,7 @@ ||117.213.15.238^ ||117.213.15.29^ ||117.213.15.43^ +||117.213.15.72^ ||117.213.40.100^ ||117.213.40.102^ ||117.213.40.107^ @@ -120941,6 +120952,7 @@ ||117.215.208.11^ ||117.215.208.143^ ||117.215.208.149^ +||117.215.208.14^ ||117.215.208.153^ ||117.215.208.156^ ||117.215.208.176^ @@ -123258,6 +123270,7 @@ ||117.222.169.229^ ||117.222.169.22^ ||117.222.169.231^ +||117.222.169.232^ ||117.222.169.234^ ||117.222.169.236^ ||117.222.169.239^ @@ -129854,6 +129867,7 @@ ||118.24.9.62^ ||118.246.199.1^ ||118.246.246.125^ +||118.246.38.170^ ||118.249.136.112^ ||118.249.136.98^ ||118.249.137.218^ @@ -151897,6 +151911,7 @@ ||123.14.248.189^ ||123.14.248.19^ ||123.14.248.208^ +||123.14.248.210^ ||123.14.248.212^ ||123.14.248.216^ ||123.14.248.221^ @@ -153319,6 +153334,7 @@ ||123.159.30.49^ ||123.159.31.110^ ||123.159.51.112^ +||123.159.68.119^ ||123.159.68.151^ ||123.159.68.26^ ||123.159.68.31^ @@ -153595,6 +153611,7 @@ ||123.191.6.244^ ||123.191.6.93^ ||123.191.60.197^ +||123.191.62.239^ ||123.191.63.187^ ||123.191.7.209^ ||123.191.79.120^ @@ -162356,7 +162373,6 @@ ||123moviesfx.com^ ||123sellfast.com^ ||123sex.co^ -||123tadi.com^ ||123xyz.xyz^ ||124.100.74.153^ ||124.105.105.222^ @@ -202115,6 +202131,7 @@ ||178.141.47.227^ ||178.141.47.70^ ||178.141.48.109^ +||178.141.48.178^ ||178.141.48.43^ ||178.141.48.82^ ||178.141.49.101^ @@ -202599,6 +202616,7 @@ ||178.175.100.70^ ||178.175.100.75^ ||178.175.100.77^ +||178.175.100.7^ ||178.175.100.81^ ||178.175.100.82^ ||178.175.100.87^ @@ -202775,6 +202793,7 @@ ||178.175.102.211^ ||178.175.102.214^ ||178.175.102.216^ +||178.175.102.219^ ||178.175.102.220^ ||178.175.102.221^ ||178.175.102.223^ @@ -203906,6 +203925,7 @@ ||178.175.112.138^ ||178.175.112.139^ ||178.175.112.13^ +||178.175.112.140^ ||178.175.112.147^ ||178.175.112.148^ ||178.175.112.150^ @@ -206281,6 +206301,7 @@ ||178.175.18.2^ ||178.175.18.32^ ||178.175.18.36^ +||178.175.18.37^ ||178.175.18.38^ ||178.175.18.42^ ||178.175.18.45^ @@ -209017,7 +209038,9 @@ ||178.175.43.215^ ||178.175.43.217^ ||178.175.43.220^ +||178.175.43.223^ ||178.175.43.227^ +||178.175.43.229^ ||178.175.43.22^ ||178.175.43.231^ ||178.175.43.232^ @@ -209105,6 +209128,7 @@ ||178.175.44.158^ ||178.175.44.162^ ||178.175.44.165^ +||178.175.44.166^ ||178.175.44.168^ ||178.175.44.169^ ||178.175.44.171^ @@ -212133,6 +212157,7 @@ ||178.175.71.174^ ||178.175.71.175^ ||178.175.71.178^ +||178.175.71.179^ ||178.175.71.17^ ||178.175.71.180^ ||178.175.71.185^ @@ -212857,6 +212882,7 @@ ||178.175.78.234^ ||178.175.78.236^ ||178.175.78.240^ +||178.175.78.242^ ||178.175.78.243^ ||178.175.78.244^ ||178.175.78.246^ @@ -214975,6 +215001,7 @@ ||178.175.97.110^ ||178.175.97.111^ ||178.175.97.112^ +||178.175.97.113^ ||178.175.97.116^ ||178.175.97.118^ ||178.175.97.123^ @@ -217500,6 +217527,7 @@ ||180.188.241.18^ ||180.188.241.194^ ||180.188.241.201^ +||180.188.241.203^ ||180.188.241.215^ ||180.188.241.216^ ||180.188.241.219^ @@ -240019,6 +240047,7 @@ ||182.121.26.242^ ||182.121.26.251^ ||182.121.26.35^ +||182.121.26.37^ ||182.121.26.56^ ||182.121.26.58^ ||182.121.26.77^ @@ -272296,6 +272325,7 @@ ||202.164.138.195^ ||202.164.138.196^ ||202.164.138.197^ +||202.164.138.19^ ||202.164.138.200^ ||202.164.138.201^ ||202.164.138.202^ @@ -276891,6 +276921,7 @@ ||209.14.30.183^ ||209.14.30.204^ ||209.14.30.205^ +||209.14.30.209^ ||209.14.30.212^ ||209.14.30.213^ ||209.14.30.216^ @@ -276917,6 +276948,7 @@ ||209.14.31.190^ ||209.14.31.192^ ||209.14.31.201^ +||209.14.31.209^ ||209.14.31.215^ ||209.14.31.217^ ||209.14.31.220^ @@ -276929,6 +276961,7 @@ ||209.14.31.243^ ||209.14.31.244^ ||209.14.31.247^ +||209.14.31.249^ ||209.14.31.252^ ||209.14.31.253^ ||209.14.31.55^ @@ -277497,6 +277530,7 @@ ||210.18.189.89^ ||210.18.189.90^ ||210.18.189.9^ +||210.180.17.140^ ||210.180.237.212^ ||210.182.101.144^ ||210.182.148.126^ @@ -290467,6 +290501,7 @@ ||220.133.1.130^ ||220.133.103.166^ ||220.133.109.249^ +||220.133.110.157^ ||220.133.114.189^ ||220.133.115.57^ ||220.133.117.229^ @@ -316242,6 +316277,7 @@ ||27.210.29.26^ ||27.210.29.83^ ||27.210.3.50^ +||27.210.32.122^ ||27.210.32.123^ ||27.210.32.125^ ||27.210.32.130^ @@ -317685,6 +317721,7 @@ ||27.216.116.240^ ||27.216.116.81^ ||27.216.117.178^ +||27.216.117.54^ ||27.216.118.234^ ||27.216.119.219^ ||27.216.119.228^ @@ -346923,6 +346960,7 @@ ||36.248.227.203^ ||36.248.228.64^ ||36.248.82.234^ +||36.248.83.98^ ||36.248.88.35^ ||36.248.92.154^ ||36.248.93.13^ @@ -362404,6 +362442,7 @@ ||42.226.83.71^ ||42.226.83.78^ ||42.226.83.98^ +||42.226.85.236^ ||42.226.86.204^ ||42.226.87.123^ ||42.226.88.114^ @@ -364694,6 +364733,7 @@ ||42.228.39.194^ ||42.228.39.197^ ||42.228.39.204^ +||42.228.39.211^ ||42.228.39.212^ ||42.228.39.214^ ||42.228.39.215^ @@ -372446,6 +372486,7 @@ ||42.232.81.147^ ||42.232.81.149^ ||42.232.81.176^ +||42.232.81.179^ ||42.232.81.181^ ||42.232.81.183^ ||42.232.81.188^ @@ -386683,6 +386724,7 @@ ||49.117.191.46^ ||49.117.191.78^ ||49.117.191.83^ +||49.119.187.230^ ||49.119.188.56^ ||49.119.189.124^ ||49.119.189.223^ @@ -390365,6 +390407,7 @@ ||58.248.142.212^ ||58.248.142.214^ ||58.248.142.223^ +||58.248.142.227^ ||58.248.142.230^ ||58.248.142.236^ ||58.248.142.237^ @@ -391603,6 +391646,7 @@ ||58.249.79.149^ ||58.249.79.163^ ||58.249.79.16^ +||58.249.79.174^ ||58.249.79.175^ ||58.249.79.17^ ||58.249.79.188^ @@ -391800,6 +391844,7 @@ ||58.249.84.11^ ||58.249.84.124^ ||58.249.84.128^ +||58.249.84.131^ ||58.249.84.134^ ||58.249.84.148^ ||58.249.84.150^ @@ -403295,6 +403340,7 @@ ||59.96.37.121^ ||59.96.37.122^ ||59.96.37.123^ +||59.96.37.124^ ||59.96.37.125^ ||59.96.37.127^ ||59.96.37.128^ @@ -407717,6 +407763,7 @@ ||59.99.43.187^ ||59.99.43.18^ ||59.99.43.190^ +||59.99.43.191^ ||59.99.43.192^ ||59.99.43.193^ ||59.99.43.194^ @@ -430553,6 +430600,7 @@ ||61.53.89.199^ ||61.53.89.1^ ||61.53.89.208^ +||61.53.89.220^ ||61.53.89.221^ ||61.53.89.227^ ||61.53.89.232^ @@ -431632,6 +431680,7 @@ ||61.54.69.62^ ||61.54.69.69^ ||61.54.69.70^ +||61.54.69.77^ ||61.54.69.78^ ||61.54.69.8^ ||61.54.69.95^ @@ -445984,7 +446033,6 @@ ||app.boxrcdn.com^ ||app.bridgeimpex.org^ ||app.calag.at^ -||app.casetabs.com^ ||app.catholicchurch.co.in^ ||app.choiphui.com^ ||app.cloudindustry.net^ @@ -450216,6 +450264,7 @@ ||beansmedia.com^ ||beanssur.com^ ||beantreefoods.com^ +||beanx88.xyz^ ||beanz-network.com^ ||bearcatpumps.com.cn^ ||beard-companies.com^ @@ -456517,7 +456566,6 @@ ||cdndownloadlp.club^ ||cdnmultimedia.com^ ||cdnpic.mgyun.com^ -||cdnrep.reimageplus.com^ ||cdnxh.net^ ||cdoconsult.com.br^ ||cdolechon.com^ @@ -457260,7 +457308,6 @@ ||cheapgadgets-gq.000webhostapp.com^ ||cheapistan.pk^ ||cheapmlbjerseysmarlins.com^ -||cheapmusic.info^ ||cheapoakleysunglasses.net^ ||cheappigeontraps.com^ ||cheapraccoontraps.com^ @@ -457309,7 +457356,6 @@ ||cheematransxpressinc.com^ ||cheerchile.cl^ ||cheerfulgiversneverlack.com^ -||cheerfullydo.com^ ||cheesecakery.com.br^ ||cheetahridge.mediadevstaging.com^ ||chef-solutions.dreamscape.co.in^ @@ -457748,6 +457794,7 @@ ||christinablunsum.com^ ||christinailoveyousomuchyoumyheart.duckdns.org^ ||christinalenway.com^ +||christinekeller.ch^ ||christinelebeck.com^ ||christinmunsch.com^ ||christmasatredeemer.org^ @@ -463318,6 +463365,7 @@ ||demo.jrkcompany.com^ ||demo.kalapifoods.com^ ||demo.kanapebudapest.hu^ +||demo.kechuahangdidong.com^ ||demo.kzonetechnologies.com^ ||demo.lamppostmedia.in^ ||demo.lapizblanco.com^ @@ -465382,7 +465430,6 @@ ||dl-675423.store-downloads.com^ ||dl-80076342.md-downloads.com^ ||dl-97674424.md-downloads.com^ -||dl-gameplayer.dmm.com^ ||dl-link.link^ ||dl-link.live^ ||dl-link.network^ @@ -465413,7 +465460,6 @@ ||dl.rina-roleplay.com^ ||dl.river-store.com^ ||dl.rp-soft.ir^ -||dl.softservers.net^ ||dl.svcupdate.com^ ||dl.teeqee.com^ ||dl.x420.me^ @@ -466216,8 +466262,10 @@ ||down.post-gg.top^ ||down.postch-b.top^ ||down.postch-bsw.top^ +||down.postch-de.top^ ||down.postch-dfa.top^ ||down.postch-dj.top^ +||down.postch-dl.top^ ||down.postch-fa.top^ ||down.postch-fj.top^ ||down.postch-kf.top^ @@ -468028,7 +468076,6 @@ ||economiadigital.biz^ ||economika.com.ve^ ||economizei.shop^ -||economplast.com^ ||economywindowcleaner.com^ ||econoteen.fea.usp.br^ ||econotel.us^ @@ -472737,7 +472784,6 @@ ||files.dropmybin.me^ ||files.enjin.com^ ||files.gathercdn.com^ -||files.hrloo.com^ ||files.l-d.tech^ ||files.martellexpress.us^ ||files.mirai-2viv.vn^ @@ -474950,6 +474996,7 @@ ||fv1-2.failiem.lv^ ||fv13.failiem.lv^ ||fv15.failiem.lv^ +||fv2-2.failiem.lv^ ||fv2-7.failiem.lv^ ||fv3.failiem.lv^ ||fv6.failiem.lv^ @@ -479193,7 +479240,6 @@ ||hangtrentroi.com^ ||hangulcafes.ga^ ||hanh.cz^ -||hanhtrinhtamlinh.com^ ||hanhtrinhthanhnienkhoinghiep.vn^ ||haniamarket.com^ ||hanict.org.vn^ @@ -479388,7 +479434,6 @@ ||harriscustomcatering.com^ ||harrisheatpumps.nz^ ||harrisnewtech.ir^ -||harrisoncarter.com^ ||harrisonlily.co.uk^ ||harryfang.com^ ||harryhiggins.com^ @@ -482189,7 +482234,6 @@ ||i-supportcharity.com^ ||i-vnsweyu.pl^ ||i-voda.com^ -||i.fiery.me^ ||i.fluffy.cc^ ||i.funtourspt.eu^ ||i.ooxx.ooo^ @@ -488570,6 +488614,7 @@ ||kec-cendana.enrekangkab.go.id^ ||kec-wlingi.blitarkab.go.id^ ||kecforging.com^ +||kechuahangdidong.com^ ||keciorenkoltukyikama.net^ ||keckarangdadap.pekalongankab.go.id^ ||kecsfila.hu^ @@ -506373,6 +506418,7 @@ ||ossandonycia.cl^ ||osscaar.com^ ||osservatore.betacom.it^ +||ossi4.51cto.com^ ||ossianlaw.com^ ||osslusturv.com^ ||ossoriobouliz.com^ @@ -509705,6 +509751,7 @@ ||politrix.net^ ||poliyzsl.host^ ||poljimenez.com^ +||polk.k12.ga.us^ ||polka32.ru^ ||polkapower.com^ ||polkolonieb4k.pl^ @@ -510876,7 +510923,6 @@ ||professionalwaiterskollege.org^ ||professionelelit.com^ ||professorsgallery.com^ -||profetestruec.net^ ||profexsystem.com^ ||proffessia.ru^ ||proffice.com.pl^ @@ -511254,6 +511300,7 @@ ||protech.mn^ ||protechcarpetcare.com^ ||protechgroup1.com^ +||protect.mimecast-offshore.com^ ||protectiadatelor.biz^ ||protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org^ ||protection.pecol.eu^ @@ -519360,7 +519407,6 @@ ||sharebook.tk^ ||sharechautari.com^ ||shared-cnd.com^ -||shared.pdffiller.com^ ||shareddocuments.ml^ ||shareddynamics.com^ ||sharedeconomy.eu^ @@ -524992,6 +525038,7 @@ ||supadom.fr^ ||supamidland-my.sharepoint.com^ ||supcargo.com^ +||supdate.mediaweb.co.kr^ ||super-filtr.ru^ ||super-gamezer.com^ ||super-industries.co^ @@ -529610,7 +529657,6 @@ ||tldrbox.top^ ||tlextreme.com^ ||tlfthelifefactory.com.au^ -||tlgur.com^ ||tlkcloudem.com^ ||tlktdsfj.sha58.me^ ||tlpclient.site^ @@ -531246,6 +531292,7 @@ ||tsr-mark.xyz^ ||tsredco.telangana.gov.in^ ||tsrj.monster^ +||tsrv2.top^ ||tst.marineindust.com^ ||tstfrigo.com^ ||tsugite.youbi.me^ @@ -532657,6 +532704,7 @@ ||update-prog.com^ ||update-res.100public.com^ ||update.5v.pl^ +||update.7h4uk.com^ ||update.att.tools^ ||update.bracncet.net^ ||update.bruss.org.ru^ @@ -532896,6 +532944,7 @@ ||url-validation-clients.com^ ||url.246546.com^ ||url.57569.fr.snd52.ch^ +||url2.mailanyone.net^ ||url3.mailanyone.net^ ||url5459.41southbar.com^ ||url675.textilmallorca.com^ @@ -534294,7 +534343,6 @@ ||viettrust-vn.net^ ||vietucgroup.org^ ||vietup.net^ -||vietvictory.vn^ ||vievioparapija.eu^ ||view-indonesia.com^ ||view-your-website.com^ @@ -534748,6 +534796,7 @@ ||visualblends.com^ ||visualdata.ru^ ||visualdimensioniq.com^ +||visualdive.com^ ||visualendodontics.net^ ||visualgag.co.uk^ ||visualhome.cl^ @@ -535826,7 +535875,6 @@ ||wc3prince.ru^ ||wcare.nl^ ||wcbgroup.co.uk^ -||wcdownloadercdn.lavasoft.com^ ||wcdr.pbas.es^ ||wcf-old.sibcat.info^ ||wcfamlaw.com^ @@ -537492,6 +537540,7 @@ ||workingonit.site^ ||workingpainters.com^ ||workingroofers.com^ +||workingsolutionsrome.org^ ||workingwell.club^ ||worklinic.com.br^ ||workmate-sien.com^ @@ -539858,7 +539907,6 @@ ||yoyoso.nz^ ||yoyoteacher.cn^ ||yp.dcyazilim.com^ -||yp.hnggzyjy.cn^ ||ypbb.or.id^ ||ypddf.org^ ||ypicsdy.cf^ @@ -540807,6 +540855,7 @@ ||zoox.com.br^ ||zoparo.nl^ ||zopbxtjiuykhyyp.usa.cc^ +||zopro.duckdns.org^ ||zoracle.com^ ||zorancreative.com^ ||zoratech.ro^ diff --git a/urlhaus-filter-bind-online.conf b/urlhaus-filter-bind-online.conf index 234c38e4..4eba22ba 100644 --- a/urlhaus-filter-bind-online.conf +++ b/urlhaus-filter-bind-online.conf @@ -1,5 +1,5 @@ # Title: Online Malicious Domains BIND Blocklist -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -16,7 +16,6 @@ zone "360.lcy2zzx.pw" { type master; notify no; file "null.zone.file"; }; zone "360down7.miiyun.cn" { type master; notify no; file "null.zone.file"; }; zone "77st.net" { type master; notify no; file "null.zone.file"; }; zone "8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com" { type master; notify no; file "null.zone.file"; }; -zone "87du.vip" { type master; notify no; file "null.zone.file"; }; zone "8poieq.bn.files.1drv.com" { type master; notify no; file "null.zone.file"; }; zone "aatreefelling.co.za" { type master; notify no; file "null.zone.file"; }; zone "abad.tv" { type master; notify no; file "null.zone.file"; }; @@ -77,6 +76,7 @@ zone "anadelgbt.org" { type master; notify no; file "null.zone.file"; }; zone "anantam.net.in" { type master; notify no; file "null.zone.file"; }; zone "andreelapeyre.com" { type master; notify no; file "null.zone.file"; }; zone "andremaraisbeleggings.co.za" { type master; notify no; file "null.zone.file"; }; +zone "andreonemaia.com" { type master; notify no; file "null.zone.file"; }; zone "andres.ac.ug" { type master; notify no; file "null.zone.file"; }; zone "andres.ug" { type master; notify no; file "null.zone.file"; }; zone "andreshconcejal.solucioneslink.com" { type master; notify no; file "null.zone.file"; }; @@ -86,7 +86,6 @@ zone "angloteste.bigprime.com.br" { type master; notify no; file "null.zone.file zone "anhung1102.vn" { type master; notify no; file "null.zone.file"; }; zone "anurontv.com" { type master; notify no; file "null.zone.file"; }; zone "anysbergbiltong.co.za" { type master; notify no; file "null.zone.file"; }; -zone "apartamentoscitta.com" { type master; notify no; file "null.zone.file"; }; zone "api-ms.cobainaja.id" { type master; notify no; file "null.zone.file"; }; zone "api.cstdevs.com" { type master; notify no; file "null.zone.file"; }; zone "api.quocbao.biz" { type master; notify no; file "null.zone.file"; }; @@ -109,15 +108,17 @@ zone "atlasconcreteworks.com" { type master; notify no; file "null.zone.file"; } zone "attach.66rpg.com" { type master; notify no; file "null.zone.file"; }; zone "atteuqpotentialunlimited.com" { type master; notify no; file "null.zone.file"; }; zone "augustair.com" { type master; notify no; file "null.zone.file"; }; +zone "aulist.com" { type master; notify no; file "null.zone.file"; }; +zone "automaticrefreshments.com" { type master; notify no; file "null.zone.file"; }; zone "avadhanagames.com" { type master; notify no; file "null.zone.file"; }; zone "ayahuascasp.com.br" { type master; notify no; file "null.zone.file"; }; zone "ayamallah.com" { type master; notify no; file "null.zone.file"; }; +zone "aycconsultoriaempresarial.com" { type master; notify no; file "null.zone.file"; }; zone "azmeasurement.com" { type master; notify no; file "null.zone.file"; }; zone "b2b.toptanakaryakit.com.tr" { type master; notify no; file "null.zone.file"; }; zone "backgrounds.pk" { type master; notify no; file "null.zone.file"; }; zone "badeggdesign.com" { type master; notify no; file "null.zone.file"; }; zone "balealgodon.mx" { type master; notify no; file "null.zone.file"; }; -zone "ballina.andrewmaughan.com" { type master; notify no; file "null.zone.file"; }; zone "bangkok-orchids.com" { type master; notify no; file "null.zone.file"; }; zone "bangladeshunbound.com" { type master; notify no; file "null.zone.file"; }; zone "bary.sz4h.com" { type master; notify no; file "null.zone.file"; }; @@ -128,6 +129,7 @@ zone "bbia.co.uk" { type master; notify no; file "null.zone.file"; }; zone "bcmt.elin.co.za" { type master; notify no; file "null.zone.file"; }; zone "bcrg.co.za" { type master; notify no; file "null.zone.file"; }; zone "bdnextrend.xyz" { type master; notify no; file "null.zone.file"; }; +zone "beanx88.xyz" { type master; notify no; file "null.zone.file"; }; zone "bearcatpumps.com.cn" { type master; notify no; file "null.zone.file"; }; zone "beautincollagen.rs" { type master; notify no; file "null.zone.file"; }; zone "bekape.co.id" { type master; notify no; file "null.zone.file"; }; @@ -135,6 +137,7 @@ zone "beor360.com" { type master; notify no; file "null.zone.file"; }; zone "bespokeweddings.ie" { type master; notify no; file "null.zone.file"; }; zone "bestcarenepal.com" { type master; notify no; file "null.zone.file"; }; zone "betone.co.kr" { type master; notify no; file "null.zone.file"; }; +zone "betycopaints.com" { type master; notify no; file "null.zone.file"; }; zone "beveragesmiami.solucioneslink.com" { type master; notify no; file "null.zone.file"; }; zone "bhavaniengineering.com" { type master; notify no; file "null.zone.file"; }; zone "bigmikesupplies.co.za" { type master; notify no; file "null.zone.file"; }; @@ -163,6 +166,7 @@ zone "bophelocare.co.za" { type master; notify no; file "null.zone.file"; }; zone "bounces.mi-fs.com" { type master; notify no; file "null.zone.file"; }; zone "boutiqueofferte.com" { type master; notify no; file "null.zone.file"; }; zone "bpo.correct.go.th" { type master; notify no; file "null.zone.file"; }; +zone "bradleyinstitute.co.za" { type master; notify no; file "null.zone.file"; }; zone "brandtrust.com.pk" { type master; notify no; file "null.zone.file"; }; zone "braunfinancial.com.au" { type master; notify no; file "null.zone.file"; }; zone "brendanquine.com" { type master; notify no; file "null.zone.file"; }; @@ -213,6 +217,7 @@ zone "chezalice.co.za" { type master; notify no; file "null.zone.file"; }; zone "childselect.com" { type master; notify no; file "null.zone.file"; }; zone "chinhdropfile.myvnc.com" { type master; notify no; file "null.zone.file"; }; zone "chinhdropfile80.myvnc.com" { type master; notify no; file "null.zone.file"; }; +zone "chipmania.it" { type master; notify no; file "null.zone.file"; }; zone "cible-energy.com" { type master; notify no; file "null.zone.file"; }; zone "cifeer.net" { type master; notify no; file "null.zone.file"; }; zone "cirugiadenarizbucaramanga.com" { type master; notify no; file "null.zone.file"; }; @@ -226,10 +231,9 @@ zone "cloud.fc.co.mz" { type master; notify no; file "null.zone.file"; }; zone "cm-arquitetos.com" { type master; notify no; file "null.zone.file"; }; zone "codsambal.com" { type master; notify no; file "null.zone.file"; }; zone "colempaques.info" { type master; notify no; file "null.zone.file"; }; -zone "colinde.pricesne.com" { type master; notify no; file "null.zone.file"; }; zone "colorpak.pl" { type master; notify no; file "null.zone.file"; }; +zone "columbia.aula-web.net" { type master; notify no; file "null.zone.file"; }; zone "community.reimclub.com" { type master; notify no; file "null.zone.file"; }; -zone "comosairdoburaco.com.br" { type master; notify no; file "null.zone.file"; }; zone "competancy.indigoconsult.net" { type master; notify no; file "null.zone.file"; }; zone "conceptimagine.ro" { type master; notify no; file "null.zone.file"; }; zone "config.cqhbkjzx.com" { type master; notify no; file "null.zone.file"; }; @@ -245,7 +249,6 @@ zone "covid19.cyberschool.or.id" { type master; notify no; file "null.zone.file" zone "cpanel.shivay.net" { type master; notify no; file "null.zone.file"; }; zone "cr-sq.com" { type master; notify no; file "null.zone.file"; }; zone "craftech.nxtnet.ga" { type master; notify no; file "null.zone.file"; }; -zone "crearechile.cl" { type master; notify no; file "null.zone.file"; }; zone "creationskateboards.com" { type master; notify no; file "null.zone.file"; }; zone "crecerco.com" { type master; notify no; file "null.zone.file"; }; zone "crittersbythebay.com" { type master; notify no; file "null.zone.file"; }; @@ -255,7 +258,6 @@ zone "crmroche.manivelasst.com" { type master; notify no; file "null.zone.file"; zone "crscorretordeimoveis.com.br" { type master; notify no; file "null.zone.file"; }; zone "cse-engineer.com" { type master; notify no; file "null.zone.file"; }; zone "csnserver.com" { type master; notify no; file "null.zone.file"; }; -zone "ctracknxt.in" { type master; notify no; file "null.zone.file"; }; zone "cubescargoexpress.com" { type master; notify no; file "null.zone.file"; }; zone "curasoles.co.za" { type master; notify no; file "null.zone.file"; }; zone "currantmedia.com" { type master; notify no; file "null.zone.file"; }; @@ -274,7 +276,6 @@ zone "data.cdevelop.org" { type master; notify no; file "null.zone.file"; }; zone "data.over-blog-kiwi.com" { type master; notify no; file "null.zone.file"; }; zone "datapolish.com" { type master; notify no; file "null.zone.file"; }; zone "dating.khokhas.co.za" { type master; notify no; file "null.zone.file"; }; -zone "datsom.vn" { type master; notify no; file "null.zone.file"; }; zone "davethompson.me.uk" { type master; notify no; file "null.zone.file"; }; zone "davidmcguinness.info" { type master; notify no; file "null.zone.file"; }; zone "dayspringdaisies.com" { type master; notify no; file "null.zone.file"; }; @@ -298,7 +299,6 @@ zone "destinymc.co.za" { type master; notify no; file "null.zone.file"; }; zone "detorre.es" { type master; notify no; file "null.zone.file"; }; zone "dev.sebpo.net" { type master; notify no; file "null.zone.file"; }; zone "dev.watch-store.eu" { type master; notify no; file "null.zone.file"; }; -zone "dezcom.com" { type master; notify no; file "null.zone.file"; }; zone "dfcf.91756.cn" { type master; notify no; file "null.zone.file"; }; zone "dfsfcsfcdsfsdvcfsvcscv.com" { type master; notify no; file "null.zone.file"; }; zone "diamantenegro.mi-fs.com" { type master; notify no; file "null.zone.file"; }; @@ -313,6 +313,7 @@ zone "dl.installcdn-aws.com" { type master; notify no; file "null.zone.file"; }; zone "dl.packetstormsecurity.net" { type master; notify no; file "null.zone.file"; }; zone "dl.rina-roleplay.com" { type master; notify no; file "null.zone.file"; }; zone "dnn.alibuf.com" { type master; notify no; file "null.zone.file"; }; +zone "dns.alibuf.com" { type master; notify no; file "null.zone.file"; }; zone "dns.cyberium.cc" { type master; notify no; file "null.zone.file"; }; zone "dockerupdate.anondns.net" { type master; notify no; file "null.zone.file"; }; zone "docman.orientalservices.in" { type master; notify no; file "null.zone.file"; }; @@ -329,6 +330,8 @@ zone "dosame.com" { type master; notify no; file "null.zone.file"; }; zone "dosman.pl" { type master; notify no; file "null.zone.file"; }; zone "dovberger.com" { type master; notify no; file "null.zone.file"; }; zone "down.pcclear.com" { type master; notify no; file "null.zone.file"; }; +zone "down.postch-de.top" { type master; notify no; file "null.zone.file"; }; +zone "down.postch-dl.top" { type master; notify no; file "null.zone.file"; }; zone "down.udashi.com" { type master; notify no; file "null.zone.file"; }; zone "down.webbora.com" { type master; notify no; file "null.zone.file"; }; zone "down1.arpun.com" { type master; notify no; file "null.zone.file"; }; @@ -388,14 +391,13 @@ zone "extrovertoffers.com" { type master; notify no; file "null.zone.file"; }; zone "f1sol.com" { type master; notify no; file "null.zone.file"; }; zone "fahrzeugdrive.com" { type master; notify no; file "null.zone.file"; }; zone "familydentist.site" { type master; notify no; file "null.zone.file"; }; -zone "faveraprojects.com" { type master; notify no; file "null.zone.file"; }; zone "fc.co.mz" { type master; notify no; file "null.zone.file"; }; zone "felicienne.nl" { type master; notify no; file "null.zone.file"; }; zone "files.martellexpress.us" { type master; notify no; file "null.zone.file"; }; zone "filmotainment.com" { type master; notify no; file "null.zone.file"; }; zone "final.makkahkmcc.com" { type master; notify no; file "null.zone.file"; }; zone "fineartgallerym.com" { type master; notify no; file "null.zone.file"; }; -zone "fisconline.casa" { type master; notify no; file "null.zone.file"; }; +zone "fisconline.bar" { type master; notify no; file "null.zone.file"; }; zone "fix-america-now.org" { type master; notify no; file "null.zone.file"; }; zone "fixauto.illumetechnology.com" { type master; notify no; file "null.zone.file"; }; zone "fixturegovernment.com" { type master; notify no; file "null.zone.file"; }; @@ -410,7 +412,6 @@ zone "foothills.com.br" { type master; notify no; file "null.zone.file"; }; zone "footweardirect.elin.co.za" { type master; notify no; file "null.zone.file"; }; zone "forum.mdb.nu" { type master; notify no; file "null.zone.file"; }; zone "fotoobjetivo.com" { type master; notify no; file "null.zone.file"; }; -zone "foundationrepairhoustontx.net" { type master; notify no; file "null.zone.file"; }; zone "foxeps.com.br" { type master; notify no; file "null.zone.file"; }; zone "fraud.bpcbankingtech.com" { type master; notify no; file "null.zone.file"; }; zone "freecnetdownload.com" { type master; notify no; file "null.zone.file"; }; @@ -419,7 +420,6 @@ zone "ftp.n3twork30cm.ml" { type master; notify no; file "null.zone.file"; }; zone "fullelectronica.com.ar" { type master; notify no; file "null.zone.file"; }; zone "funletters.net" { type master; notify no; file "null.zone.file"; }; zone "fusionfiresolutions.com" { type master; notify no; file "null.zone.file"; }; -zone "futbolpr.com" { type master; notify no; file "null.zone.file"; }; zone "futuregraphics.com.ar" { type master; notify no; file "null.zone.file"; }; zone "g.pinmonkey.xyz" { type master; notify no; file "null.zone.file"; }; zone "gametwogame.com" { type master; notify no; file "null.zone.file"; }; @@ -436,6 +436,7 @@ zone "ghettohub.co.za" { type master; notify no; file "null.zone.file"; }; zone "ghislain.dartois.pagesperso-orange.fr" { type master; notify no; file "null.zone.file"; }; zone "giadungg7.com" { type master; notify no; file "null.zone.file"; }; zone "giddos.ga" { type master; notify no; file "null.zone.file"; }; +zone "giteletropical.com" { type master; notify no; file "null.zone.file"; }; zone "glowinmedia.co.ke" { type master; notify no; file "null.zone.file"; }; zone "gmsebpl.com" { type master; notify no; file "null.zone.file"; }; zone "gmtransformationacademy.com" { type master; notify no; file "null.zone.file"; }; @@ -448,6 +449,7 @@ zone "goldcoastoffice365.com" { type master; notify no; file "null.zone.file"; } zone "goldcoastoffice365.com.au" { type master; notify no; file "null.zone.file"; }; zone "golden-memories-funerals.yourpageserver.com" { type master; notify no; file "null.zone.file"; }; zone "goldenasiacapital.com" { type master; notify no; file "null.zone.file"; }; +zone "goldmen.in" { type master; notify no; file "null.zone.file"; }; zone "gorecycle.fahadjutt.com" { type master; notify no; file "null.zone.file"; }; zone "gpotecnosystems.com" { type master; notify no; file "null.zone.file"; }; zone "gracejukes.com" { type master; notify no; file "null.zone.file"; }; @@ -476,13 +478,12 @@ zone "hhaward.org" { type master; notify no; file "null.zone.file"; }; zone "highlandroadcoc.com" { type master; notify no; file "null.zone.file"; }; zone "highlandslasvegas.atakdev.com" { type master; notify no; file "null.zone.file"; }; zone "hindi.factsriver.com" { type master; notify no; file "null.zone.file"; }; -zone "hiptool.net" { type master; notify no; file "null.zone.file"; }; zone "hitpe.com" { type master; notify no; file "null.zone.file"; }; zone "hitstation.nl" { type master; notify no; file "null.zone.file"; }; +zone "hlmd.in" { type master; notify no; file "null.zone.file"; }; zone "hmpmall.co.kr" { type master; notify no; file "null.zone.file"; }; zone "hoagietesting10.com" { type master; notify no; file "null.zone.file"; }; zone "hoayeuthuong-my.sharepoint.com" { type master; notify no; file "null.zone.file"; }; -zone "holmesservices.mobiledevsite.co" { type master; notify no; file "null.zone.file"; }; zone "homefindersolutions.com" { type master; notify no; file "null.zone.file"; }; zone "hongluosi.com" { type master; notify no; file "null.zone.file"; }; zone "hookedupboatclub.com" { type master; notify no; file "null.zone.file"; }; @@ -493,7 +494,6 @@ zone "houstonshutters.site" { type master; notify no; file "null.zone.file"; }; zone "hr2019.vrcom7.com" { type master; notify no; file "null.zone.file"; }; zone "hrnautica.com.br" { type master; notify no; file "null.zone.file"; }; zone "hseda.com" { type master; notify no; file "null.zone.file"; }; -zone "hsmwebapp.com" { type master; notify no; file "null.zone.file"; }; zone "htownbars.com" { type master; notify no; file "null.zone.file"; }; zone "hubtech.co.za" { type master; notify no; file "null.zone.file"; }; zone "huellacero.cl" { type master; notify no; file "null.zone.file"; }; @@ -533,16 +533,19 @@ zone "ioabc.wif.com.br" { type master; notify no; file "null.zone.file"; }; zone "ipmes.ma" { type master; notify no; file "null.zone.file"; }; zone "iremart.es" { type master; notify no; file "null.zone.file"; }; zone "iris101.co.uk" { type master; notify no; file "null.zone.file"; }; +zone "isaac.mikhailmotoringschool.com" { type master; notify no; file "null.zone.file"; }; zone "iscamenabe.com" { type master; notify no; file "null.zone.file"; }; zone "isiphephelocon.co.za" { type master; notify no; file "null.zone.file"; }; zone "iso-dubai.net" { type master; notify no; file "null.zone.file"; }; zone "israrulhaq.me" { type master; notify no; file "null.zone.file"; }; +zone "isrorg.com" { type master; notify no; file "null.zone.file"; }; zone "isso.ps" { type master; notify no; file "null.zone.file"; }; zone "ist-security.com" { type master; notify no; file "null.zone.file"; }; zone "it123.ru" { type master; notify no; file "null.zone.file"; }; zone "italiandirezione.casa" { type master; notify no; file "null.zone.file"; }; zone "itc-demo.softgig.co.ke" { type master; notify no; file "null.zone.file"; }; zone "itelsys.ma" { type master; notify no; file "null.zone.file"; }; +zone "itmotasaciones.com" { type master; notify no; file "null.zone.file"; }; zone "jacktech.jackindia.com" { type master; notify no; file "null.zone.file"; }; zone "jaishritours.com" { type master; notify no; file "null.zone.file"; }; zone "jamiekaylive.com" { type master; notify no; file "null.zone.file"; }; @@ -556,6 +559,7 @@ zone "jennwolfemtb.com" { type master; notify no; file "null.zone.file"; }; zone "jhayesconsulting.com" { type master; notify no; file "null.zone.file"; }; zone "jiaoyuzixun.cn" { type master; notify no; file "null.zone.file"; }; zone "jing-da.com.tw" { type master; notify no; file "null.zone.file"; }; +zone "jmtc.91756.cn" { type master; notify no; file "null.zone.file"; }; zone "jnanbharati.com" { type master; notify no; file "null.zone.file"; }; zone "jobs.thebeessolution.com" { type master; notify no; file "null.zone.file"; }; zone "joelbonissilver.com" { type master; notify no; file "null.zone.file"; }; @@ -566,6 +570,7 @@ zone "jumpmanualjacobhiller.com" { type master; notify no; file "null.zone.file" zone "jupiter.toxsl.in" { type master; notify no; file "null.zone.file"; }; zone "justinscott.com.au" { type master; notify no; file "null.zone.file"; }; zone "kadigital.co.uk" { type master; notify no; file "null.zone.file"; }; +zone "kaizenjanitorial.com" { type master; notify no; file "null.zone.file"; }; zone "kalawatihomes.com" { type master; notify no; file "null.zone.file"; }; zone "kalogirosfinance.com" { type master; notify no; file "null.zone.file"; }; zone "kaptaanchapal.com" { type master; notify no; file "null.zone.file"; }; @@ -627,14 +632,16 @@ zone "lotusanddragonfly.com" { type master; notify no; file "null.zone.file"; }; zone "lp.definerisco.com" { type master; notify no; file "null.zone.file"; }; zone "lp.difusodesign.com" { type master; notify no; file "null.zone.file"; }; zone "lp.quama.pe" { type master; notify no; file "null.zone.file"; }; -zone "ltc.typoten.com" { type master; notify no; file "null.zone.file"; }; +zone "luckybrownie.com" { type master; notify no; file "null.zone.file"; }; zone "luminouspneuma.com" { type master; notify no; file "null.zone.file"; }; zone "luxomodels.com" { type master; notify no; file "null.zone.file"; }; zone "m-technics.kz" { type master; notify no; file "null.zone.file"; }; zone "m.estudiomoros.com.ar" { type master; notify no; file "null.zone.file"; }; zone "m.mobilelocalsales.com" { type master; notify no; file "null.zone.file"; }; +zone "m.softsharks.com" { type master; notify no; file "null.zone.file"; }; zone "madicon.co.za" { type master; notify no; file "null.zone.file"; }; zone "magianegramagiablancayamarres.com" { type master; notify no; file "null.zone.file"; }; +zone "maharaniworld.com" { type master; notify no; file "null.zone.file"; }; zone "mail.bs-eiendomme.co.za" { type master; notify no; file "null.zone.file"; }; zone "mail.golimoapp.com" { type master; notify no; file "null.zone.file"; }; zone "mail.jeffsono.org" { type master; notify no; file "null.zone.file"; }; @@ -660,7 +667,6 @@ zone "matruchhaya.co.in" { type master; notify no; file "null.zone.file"; }; zone "maxiquim.cl" { type master; notify no; file "null.zone.file"; }; zone "maxoprint.co.uk" { type master; notify no; file "null.zone.file"; }; zone "maxtox.com.pk" { type master; notify no; file "null.zone.file"; }; -zone "maybethescobar.com" { type master; notify no; file "null.zone.file"; }; zone "mbgrm.com" { type master; notify no; file "null.zone.file"; }; zone "mbjtimes.com" { type master; notify no; file "null.zone.file"; }; zone "mbsolutions.ge" { type master; notify no; file "null.zone.file"; }; @@ -691,11 +697,12 @@ zone "michaelphilip.com" { type master; notify no; file "null.zone.file"; }; zone "michimal2.000webhostapp.com" { type master; notify no; file "null.zone.file"; }; zone "microblading.mirliandias.com.br" { type master; notify no; file "null.zone.file"; }; zone "microcomm-group.com" { type master; notify no; file "null.zone.file"; }; +zone "mikhailmotoringschool.com" { type master; notify no; file "null.zone.file"; }; +zone "mills-skyla30ec.com" { type master; notify no; file "null.zone.file"; }; zone "mingguanwms.com" { type master; notify no; file "null.zone.file"; }; zone "minuevavida.org" { type master; notify no; file "null.zone.file"; }; zone "mirror.mypage.sk" { type master; notify no; file "null.zone.file"; }; zone "misterson.com" { type master; notify no; file "null.zone.file"; }; -zone "mixr.at" { type master; notify no; file "null.zone.file"; }; zone "mkontakt.az" { type master; notify no; file "null.zone.file"; }; zone "mktf.mx" { type master; notify no; file "null.zone.file"; }; zone "mmdx.com" { type master; notify no; file "null.zone.file"; }; @@ -732,6 +739,7 @@ zone "navayurveda.in" { type master; notify no; file "null.zone.file"; }; zone "nec-i.com" { type master; notify no; file "null.zone.file"; }; zone "nedkellymyanmar.com" { type master; notify no; file "null.zone.file"; }; zone "nelitrianggraeni.000webhostapp.com" { type master; notify no; file "null.zone.file"; }; +zone "nellaimasthanbiryani.com" { type master; notify no; file "null.zone.file"; }; zone "nerve.untergrund.net" { type master; notify no; file "null.zone.file"; }; zone "nettube.com.br" { type master; notify no; file "null.zone.file"; }; zone "networkwheels.co.za" { type master; notify no; file "null.zone.file"; }; @@ -756,7 +764,6 @@ zone "njtiledesigncenter.com" { type master; notify no; file "null.zone.file"; } zone "nobius.org" { type master; notify no; file "null.zone.file"; }; zone "nocalnoodle.elin.co.za" { type master; notify no; file "null.zone.file"; }; zone "nomadicbees.com" { type master; notify no; file "null.zone.file"; }; -zone "nonnarina.ax" { type master; notify no; file "null.zone.file"; }; zone "notamuzikaletleri.com" { type master; notify no; file "null.zone.file"; }; zone "ns1.the-widyantos.com" { type master; notify no; file "null.zone.file"; }; zone "nsb.org.uk" { type master; notify no; file "null.zone.file"; }; @@ -776,12 +783,15 @@ zone "omaromatic.com" { type master; notify no; file "null.zone.file"; }; zone "omega.az" { type master; notify no; file "null.zone.file"; }; zone "oms.pappai.com" { type master; notify no; file "null.zone.file"; }; zone "omscoc.pappai.com" { type master; notify no; file "null.zone.file"; }; +zone "onedigitalcard.granvizionnecorp.com" { type master; notify no; file "null.zone.file"; }; zone "onedrive.listifyapp.co" { type master; notify no; file "null.zone.file"; }; zone "online.creedglobal.in" { type master; notify no; file "null.zone.file"; }; zone "onlinestatis.bar" { type master; notify no; file "null.zone.file"; }; +zone "open.rawntech.com" { type master; notify no; file "null.zone.file"; }; zone "open.warehousesaas.co.uk" { type master; notify no; file "null.zone.file"; }; zone "opentoronto.org" { type master; notify no; file "null.zone.file"; }; zone "opolis.io" { type master; notify no; file "null.zone.file"; }; +zone "opticaoptigral.cl" { type master; notify no; file "null.zone.file"; }; zone "optimus.com.sg" { type master; notify no; file "null.zone.file"; }; zone "order.bizpeed.com" { type master; notify no; file "null.zone.file"; }; zone "orientgatewayltd.com" { type master; notify no; file "null.zone.file"; }; @@ -819,6 +829,7 @@ zone "pcsoori.com" { type master; notify no; file "null.zone.file"; }; zone "pd.oceaniarp.net" { type master; notify no; file "null.zone.file"; }; zone "pemdodo.com" { type master; notify no; file "null.zone.file"; }; zone "perfumeriamontes.es" { type master; notify no; file "null.zone.file"; }; +zone "periodiche.bar" { type master; notify no; file "null.zone.file"; }; zone "perpus.onlineman7-jombang.sch.id" { type master; notify no; file "null.zone.file"; }; zone "perpustekim.untirta.ac.id" { type master; notify no; file "null.zone.file"; }; zone "pestoclean.co.uk" { type master; notify no; file "null.zone.file"; }; @@ -838,6 +849,7 @@ zone "pmglance.startwriteup.com" { type master; notify no; file "null.zone.file" zone "pointactionsg.com" { type master; notify no; file "null.zone.file"; }; zone "pokojewewladyslawowie.pl" { type master; notify no; file "null.zone.file"; }; zone "pole.com.vc" { type master; notify no; file "null.zone.file"; }; +zone "ponchokhana.com" { type master; notify no; file "null.zone.file"; }; zone "pool.phxdir.com" { type master; notify no; file "null.zone.file"; }; zone "pooltablemoversdenver.net" { type master; notify no; file "null.zone.file"; }; zone "portal.premiumpunch.com" { type master; notify no; file "null.zone.file"; }; @@ -848,6 +860,7 @@ zone "prestasicash.com.ar" { type master; notify no; file "null.zone.file"; }; zone "prestigehomeautomation.net" { type master; notify no; file "null.zone.file"; }; zone "preview2.behalen.com" { type master; notify no; file "null.zone.file"; }; zone "prishaartcreations.com" { type master; notify no; file "null.zone.file"; }; +zone "prismaxis.com" { type master; notify no; file "null.zone.file"; }; zone "production.sparshims.com" { type master; notify no; file "null.zone.file"; }; zone "programaoperadoronline.com.br" { type master; notify no; file "null.zone.file"; }; zone "project.exquitec.com" { type master; notify no; file "null.zone.file"; }; @@ -899,7 +912,6 @@ zone "reseller.itechbrasil.com" { type master; notify no; file "null.zone.file"; zone "resuco.net" { type master; notify no; file "null.zone.file"; }; zone "rezkabum.ru" { type master; notify no; file "null.zone.file"; }; zone "rhema.com.sg" { type master; notify no; file "null.zone.file"; }; -zone "richancyber.info" { type master; notify no; file "null.zone.file"; }; zone "richmondminerals.co.zm" { type master; notify no; file "null.zone.file"; }; zone "rinaefoundation.org.za" { type master; notify no; file "null.zone.file"; }; zone "rinkaisystem-ht.com" { type master; notify no; file "null.zone.file"; }; @@ -908,7 +920,6 @@ zone "rkcable.co.in" { type master; notify no; file "null.zone.file"; }; zone "rkverify.securestudies.com" { type master; notify no; file "null.zone.file"; }; zone "robertmcardle.com" { type master; notify no; file "null.zone.file"; }; zone "robertsinclair.net" { type master; notify no; file "null.zone.file"; }; -zone "romanianpoints.com" { type master; notify no; file "null.zone.file"; }; zone "ronnietucker.co.uk" { type master; notify no; file "null.zone.file"; }; zone "roomsvc.servegate.kr" { type master; notify no; file "null.zone.file"; }; zone "roshnijewellery.com" { type master; notify no; file "null.zone.file"; }; @@ -918,7 +929,6 @@ zone "rubycityvietnam.com" { type master; notify no; file "null.zone.file"; }; zone "ruisgood.ru" { type master; notify no; file "null.zone.file"; }; zone "ruwadalkuwait.com" { type master; notify no; file "null.zone.file"; }; zone "rydchile.cl" { type master; notify no; file "null.zone.file"; }; -zone "s.51shijuan.com" { type master; notify no; file "null.zone.file"; }; zone "s.thechinesemuslim.com" { type master; notify no; file "null.zone.file"; }; zone "sac2.11xii.com" { type master; notify no; file "null.zone.file"; }; zone "sacredscentsonline.com" { type master; notify no; file "null.zone.file"; }; @@ -952,7 +962,9 @@ zone "serendibsourcing.com" { type master; notify no; file "null.zone.file"; }; zone "sericaasia.com" { type master; notify no; file "null.zone.file"; }; zone "servicemhkd.myvnc.com" { type master; notify no; file "null.zone.file"; }; zone "servicemhkd80.myvnc.com" { type master; notify no; file "null.zone.file"; }; +zone "serviciovirtual.com.ar" { type master; notify no; file "null.zone.file"; }; zone "sexologistpakistan.net" { type master; notify no; file "null.zone.file"; }; +zone "seyranikenger.com.tr" { type master; notify no; file "null.zone.file"; }; zone "sgb.ac.ke" { type master; notify no; file "null.zone.file"; }; zone "sgessy.com.br" { type master; notify no; file "null.zone.file"; }; zone "shaheentbfoundation.com" { type master; notify no; file "null.zone.file"; }; @@ -1003,6 +1015,7 @@ zone "spaceframe.mobi.space-frame.co.za" { type master; notify no; file "null.zo zone "special-key.cf" { type master; notify no; file "null.zone.file"; }; zone "spent.com.pl" { type master; notify no; file "null.zone.file"; }; zone "spetsesyachtcharter.gr" { type master; notify no; file "null.zone.file"; }; +zone "spiritualroot.org" { type master; notify no; file "null.zone.file"; }; zone "spititourism.com" { type master; notify no; file "null.zone.file"; }; zone "spittinfire.com" { type master; notify no; file "null.zone.file"; }; zone "sports-net.de" { type master; notify no; file "null.zone.file"; }; @@ -1022,7 +1035,7 @@ zone "stiepancasetia.ac.id" { type master; notify no; file "null.zone.file"; }; zone "stlukesohag.com" { type master; notify no; file "null.zone.file"; }; zone "store.ericalgarin.com" { type master; notify no; file "null.zone.file"; }; zone "stott-thompson.co.uk" { type master; notify no; file "null.zone.file"; }; -zone "streetdemo.yourpageserver.com" { type master; notify no; file "null.zone.file"; }; +zone "stratexec.co.za" { type master; notify no; file "null.zone.file"; }; zone "suboldesign.com" { type master; notify no; file "null.zone.file"; }; zone "sumerians.org" { type master; notify no; file "null.zone.file"; }; zone "sunaryem.com.tr" { type master; notify no; file "null.zone.file"; }; @@ -1070,6 +1083,7 @@ zone "test.lubrico.in" { type master; notify no; file "null.zone.file"; }; zone "test.typoten.com" { type master; notify no; file "null.zone.file"; }; zone "test.wanepghana.org" { type master; notify no; file "null.zone.file"; }; zone "test1.asistencia247.com" { type master; notify no; file "null.zone.file"; }; +zone "test1.milenial.id" { type master; notify no; file "null.zone.file"; }; zone "test1.tenplusone.my" { type master; notify no; file "null.zone.file"; }; zone "test2.basis-web.com" { type master; notify no; file "null.zone.file"; }; zone "test2.marrenconstruction.ie" { type master; notify no; file "null.zone.file"; }; @@ -1094,7 +1108,7 @@ zone "themansionkasauli.com" { type master; notify no; file "null.zone.file"; }; zone "theprofinn.com" { type master; notify no; file "null.zone.file"; }; zone "thesummitpc.net" { type master; notify no; file "null.zone.file"; }; zone "theurbantutors.com" { type master; notify no; file "null.zone.file"; }; -zone "thientu.net" { type master; notify no; file "null.zone.file"; }; +zone "thirdstringcalifornia.com" { type master; notify no; file "null.zone.file"; }; zone "thosewebbs.com" { type master; notify no; file "null.zone.file"; }; zone "thriveink.com" { type master; notify no; file "null.zone.file"; }; zone "tianangdep.com" { type master; notify no; file "null.zone.file"; }; @@ -1104,7 +1118,6 @@ zone "timamollo.co.za" { type master; notify no; file "null.zone.file"; }; zone "timegonebuy.com" { type master; notify no; file "null.zone.file"; }; zone "tksb.net" { type master; notify no; file "null.zone.file"; }; zone "tlcc.com.gt" { type master; notify no; file "null.zone.file"; }; -zone "tntmedia.gr" { type master; notify no; file "null.zone.file"; }; zone "todoapp.cstdevs.com" { type master; notify no; file "null.zone.file"; }; zone "todocontodo.com.mx" { type master; notify no; file "null.zone.file"; }; zone "tonydong.com" { type master; notify no; file "null.zone.file"; }; @@ -1141,6 +1154,7 @@ zone "ultimate-24.de" { type master; notify no; file "null.zone.file"; }; zone "umwelt-kirchhof.de" { type master; notify no; file "null.zone.file"; }; zone "unicorpbrunei.com" { type master; notify no; file "null.zone.file"; }; zone "uniengrisb.com" { type master; notify no; file "null.zone.file"; }; +zone "unisoftcc.com" { type master; notify no; file "null.zone.file"; }; zone "unyazitelecom.com" { type master; notify no; file "null.zone.file"; }; zone "upcbpta.com" { type master; notify no; file "null.zone.file"; }; zone "urbantrapfest.cl" { type master; notify no; file "null.zone.file"; }; @@ -1155,7 +1169,9 @@ zone "vbcargo.hu" { type master; notify no; file "null.zone.file"; }; zone "vcah.co.uk" { type master; notify no; file "null.zone.file"; }; zone "vectarts.com" { type master; notify no; file "null.zone.file"; }; zone "vegadelcasero.cl" { type master; notify no; file "null.zone.file"; }; +zone "velma-harber30ku.com" { type master; notify no; file "null.zone.file"; }; zone "vendas.lidiacarmeli.com.br" { type master; notify no; file "null.zone.file"; }; +zone "versualstudio.com" { type master; notify no; file "null.zone.file"; }; zone "veterinariadrpopui.com" { type master; notify no; file "null.zone.file"; }; zone "vfocus.net" { type master; notify no; file "null.zone.file"; }; zone "vienen.gblix.srv.br" { type master; notify no; file "null.zone.file"; }; @@ -1182,6 +1198,7 @@ zone "vvsskmodinationalschool.com" { type master; notify no; file "null.zone.fil zone "w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu" { type master; notify no; file "null.zone.file"; }; zone "wanepliberia.org" { type master; notify no; file "null.zone.file"; }; zone "wanepniger.org" { type master; notify no; file "null.zone.file"; }; +zone "weareactum.com" { type master; notify no; file "null.zone.file"; }; zone "web.eng.ubu.ac.th" { type master; notify no; file "null.zone.file"; }; zone "web.geetle.ga" { type master; notify no; file "null.zone.file"; }; zone "web.geomegasoft.net" { type master; notify no; file "null.zone.file"; }; @@ -1209,6 +1226,7 @@ zone "wolfgang-brodte.de" { type master; notify no; file "null.zone.file"; }; zone "wonderhawaii.com" { type master; notify no; file "null.zone.file"; }; zone "woodsytech.com" { type master; notify no; file "null.zone.file"; }; zone "wordpress.saleensuporte.com.br" { type master; notify no; file "null.zone.file"; }; +zone "workingsolutionsrome.org" { type master; notify no; file "null.zone.file"; }; zone "wozata.000webhostapp.com" { type master; notify no; file "null.zone.file"; }; zone "wp.readhere.in" { type master; notify no; file "null.zone.file"; }; zone "wpdemo.101clients.com.au" { type master; notify no; file "null.zone.file"; }; @@ -1230,7 +1248,6 @@ zone "yoast.yourpageserver.com" { type master; notify no; file "null.zone.file"; zone "yourclub1.com" { type master; notify no; file "null.zone.file"; }; zone "yourtopdog.com.au" { type master; notify no; file "null.zone.file"; }; zone "youtubetrainingacademy.com" { type master; notify no; file "null.zone.file"; }; -zone "yp.hnggzyjy.cn" { type master; notify no; file "null.zone.file"; }; zone "yskadvisors.com" { type master; notify no; file "null.zone.file"; }; zone "yummyyogaudaipur.com" { type master; notify no; file "null.zone.file"; }; zone "yzkzixun.com" { type master; notify no; file "null.zone.file"; }; diff --git a/urlhaus-filter-bind.conf b/urlhaus-filter-bind.conf index a16cc1aa..db870c94 100644 --- a/urlhaus-filter-bind.conf +++ b/urlhaus-filter-bind.conf @@ -1,5 +1,5 @@ # Title: Malicious Domains BIND Blocklist -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -238,7 +238,6 @@ zone "123mobile.store" { type master; notify no; file "null.zone.file"; }; zone "123moviesfx.com" { type master; notify no; file "null.zone.file"; }; zone "123sellfast.com" { type master; notify no; file "null.zone.file"; }; zone "123sex.co" { type master; notify no; file "null.zone.file"; }; -zone "123tadi.com" { type master; notify no; file "null.zone.file"; }; zone "123xyz.xyz" { type master; notify no; file "null.zone.file"; }; zone "124.com.ua" { type master; notify no; file "null.zone.file"; }; zone "124.cpanel.realwebsitesite.com" { type master; notify no; file "null.zone.file"; }; @@ -7094,7 +7093,6 @@ zone "app.bigplan-alex.com" { type master; notify no; file "null.zone.file"; }; zone "app.boxrcdn.com" { type master; notify no; file "null.zone.file"; }; zone "app.bridgeimpex.org" { type master; notify no; file "null.zone.file"; }; zone "app.calag.at" { type master; notify no; file "null.zone.file"; }; -zone "app.casetabs.com" { type master; notify no; file "null.zone.file"; }; zone "app.catholicchurch.co.in" { type master; notify no; file "null.zone.file"; }; zone "app.choiphui.com" { type master; notify no; file "null.zone.file"; }; zone "app.cloudindustry.net" { type master; notify no; file "null.zone.file"; }; @@ -11326,6 +11324,7 @@ zone "beanmatrix.com" { type master; notify no; file "null.zone.file"; }; zone "beansmedia.com" { type master; notify no; file "null.zone.file"; }; zone "beanssur.com" { type master; notify no; file "null.zone.file"; }; zone "beantreefoods.com" { type master; notify no; file "null.zone.file"; }; +zone "beanx88.xyz" { type master; notify no; file "null.zone.file"; }; zone "beanz-network.com" { type master; notify no; file "null.zone.file"; }; zone "bearcatpumps.com.cn" { type master; notify no; file "null.zone.file"; }; zone "beard-companies.com" { type master; notify no; file "null.zone.file"; }; @@ -17627,7 +17626,6 @@ zone "cdncomfortgroup.website" { type master; notify no; file "null.zone.file"; zone "cdndownloadlp.club" { type master; notify no; file "null.zone.file"; }; zone "cdnmultimedia.com" { type master; notify no; file "null.zone.file"; }; zone "cdnpic.mgyun.com" { type master; notify no; file "null.zone.file"; }; -zone "cdnrep.reimageplus.com" { type master; notify no; file "null.zone.file"; }; zone "cdnxh.net" { type master; notify no; file "null.zone.file"; }; zone "cdoconsult.com.br" { type master; notify no; file "null.zone.file"; }; zone "cdolechon.com" { type master; notify no; file "null.zone.file"; }; @@ -18370,7 +18368,6 @@ zone "cheapesthost.com.ng" { type master; notify no; file "null.zone.file"; }; zone "cheapgadgets-gq.000webhostapp.com" { type master; notify no; file "null.zone.file"; }; zone "cheapistan.pk" { type master; notify no; file "null.zone.file"; }; zone "cheapmlbjerseysmarlins.com" { type master; notify no; file "null.zone.file"; }; -zone "cheapmusic.info" { type master; notify no; file "null.zone.file"; }; zone "cheapoakleysunglasses.net" { type master; notify no; file "null.zone.file"; }; zone "cheappigeontraps.com" { type master; notify no; file "null.zone.file"; }; zone "cheapraccoontraps.com" { type master; notify no; file "null.zone.file"; }; @@ -18419,7 +18416,6 @@ zone "cheekie2.neagoeandrei.com" { type master; notify no; file "null.zone.file" zone "cheematransxpressinc.com" { type master; notify no; file "null.zone.file"; }; zone "cheerchile.cl" { type master; notify no; file "null.zone.file"; }; zone "cheerfulgiversneverlack.com" { type master; notify no; file "null.zone.file"; }; -zone "cheerfullydo.com" { type master; notify no; file "null.zone.file"; }; zone "cheesecakery.com.br" { type master; notify no; file "null.zone.file"; }; zone "cheetahridge.mediadevstaging.com" { type master; notify no; file "null.zone.file"; }; zone "chef-solutions.dreamscape.co.in" { type master; notify no; file "null.zone.file"; }; @@ -18858,6 +18854,7 @@ zone "christina.makeyourselfelaborate.com" { type master; notify no; file "null. zone "christinablunsum.com" { type master; notify no; file "null.zone.file"; }; zone "christinailoveyousomuchyoumyheart.duckdns.org" { type master; notify no; file "null.zone.file"; }; zone "christinalenway.com" { type master; notify no; file "null.zone.file"; }; +zone "christinekeller.ch" { type master; notify no; file "null.zone.file"; }; zone "christinelebeck.com" { type master; notify no; file "null.zone.file"; }; zone "christinmunsch.com" { type master; notify no; file "null.zone.file"; }; zone "christmasatredeemer.org" { type master; notify no; file "null.zone.file"; }; @@ -24428,6 +24425,7 @@ zone "demo.jjmayurved.com" { type master; notify no; file "null.zone.file"; }; zone "demo.jrkcompany.com" { type master; notify no; file "null.zone.file"; }; zone "demo.kalapifoods.com" { type master; notify no; file "null.zone.file"; }; zone "demo.kanapebudapest.hu" { type master; notify no; file "null.zone.file"; }; +zone "demo.kechuahangdidong.com" { type master; notify no; file "null.zone.file"; }; zone "demo.kzonetechnologies.com" { type master; notify no; file "null.zone.file"; }; zone "demo.lamppostmedia.in" { type master; notify no; file "null.zone.file"; }; zone "demo.lapizblanco.com" { type master; notify no; file "null.zone.file"; }; @@ -26492,7 +26490,6 @@ zone "dl-45538429.onedrives-en-live.com" { type master; notify no; file "null.zo zone "dl-675423.store-downloads.com" { type master; notify no; file "null.zone.file"; }; zone "dl-80076342.md-downloads.com" { type master; notify no; file "null.zone.file"; }; zone "dl-97674424.md-downloads.com" { type master; notify no; file "null.zone.file"; }; -zone "dl-gameplayer.dmm.com" { type master; notify no; file "null.zone.file"; }; zone "dl-link.link" { type master; notify no; file "null.zone.file"; }; zone "dl-link.live" { type master; notify no; file "null.zone.file"; }; zone "dl-link.network" { type master; notify no; file "null.zone.file"; }; @@ -26523,7 +26520,6 @@ zone "dl.repairlabshost.com" { type master; notify no; file "null.zone.file"; }; zone "dl.rina-roleplay.com" { type master; notify no; file "null.zone.file"; }; zone "dl.river-store.com" { type master; notify no; file "null.zone.file"; }; zone "dl.rp-soft.ir" { type master; notify no; file "null.zone.file"; }; -zone "dl.softservers.net" { type master; notify no; file "null.zone.file"; }; zone "dl.svcupdate.com" { type master; notify no; file "null.zone.file"; }; zone "dl.teeqee.com" { type master; notify no; file "null.zone.file"; }; zone "dl.x420.me" { type master; notify no; file "null.zone.file"; }; @@ -27326,8 +27322,10 @@ zone "down.pcclear.com" { type master; notify no; file "null.zone.file"; }; zone "down.post-gg.top" { type master; notify no; file "null.zone.file"; }; zone "down.postch-b.top" { type master; notify no; file "null.zone.file"; }; zone "down.postch-bsw.top" { type master; notify no; file "null.zone.file"; }; +zone "down.postch-de.top" { type master; notify no; file "null.zone.file"; }; zone "down.postch-dfa.top" { type master; notify no; file "null.zone.file"; }; zone "down.postch-dj.top" { type master; notify no; file "null.zone.file"; }; +zone "down.postch-dl.top" { type master; notify no; file "null.zone.file"; }; zone "down.postch-fa.top" { type master; notify no; file "null.zone.file"; }; zone "down.postch-fj.top" { type master; notify no; file "null.zone.file"; }; zone "down.postch-kf.top" { type master; notify no; file "null.zone.file"; }; @@ -29138,7 +29136,6 @@ zone "economiadeltempo.it" { type master; notify no; file "null.zone.file"; }; zone "economiadigital.biz" { type master; notify no; file "null.zone.file"; }; zone "economika.com.ve" { type master; notify no; file "null.zone.file"; }; zone "economizei.shop" { type master; notify no; file "null.zone.file"; }; -zone "economplast.com" { type master; notify no; file "null.zone.file"; }; zone "economywindowcleaner.com" { type master; notify no; file "null.zone.file"; }; zone "econoteen.fea.usp.br" { type master; notify no; file "null.zone.file"; }; zone "econotel.us" { type master; notify no; file "null.zone.file"; }; @@ -33847,7 +33844,6 @@ zone "files.danwin1210.me" { type master; notify no; file "null.zone.file"; }; zone "files.dropmybin.me" { type master; notify no; file "null.zone.file"; }; zone "files.enjin.com" { type master; notify no; file "null.zone.file"; }; zone "files.gathercdn.com" { type master; notify no; file "null.zone.file"; }; -zone "files.hrloo.com" { type master; notify no; file "null.zone.file"; }; zone "files.l-d.tech" { type master; notify no; file "null.zone.file"; }; zone "files.martellexpress.us" { type master; notify no; file "null.zone.file"; }; zone "files.mirai-2viv.vn" { type master; notify no; file "null.zone.file"; }; @@ -36060,6 +36056,7 @@ zone "fuzzymiles.com" { type master; notify no; file "null.zone.file"; }; zone "fv1-2.failiem.lv" { type master; notify no; file "null.zone.file"; }; zone "fv13.failiem.lv" { type master; notify no; file "null.zone.file"; }; zone "fv15.failiem.lv" { type master; notify no; file "null.zone.file"; }; +zone "fv2-2.failiem.lv" { type master; notify no; file "null.zone.file"; }; zone "fv2-7.failiem.lv" { type master; notify no; file "null.zone.file"; }; zone "fv3.failiem.lv" { type master; notify no; file "null.zone.file"; }; zone "fv6.failiem.lv" { type master; notify no; file "null.zone.file"; }; @@ -40303,7 +40300,6 @@ zone "hangtotma.com" { type master; notify no; file "null.zone.file"; }; zone "hangtrentroi.com" { type master; notify no; file "null.zone.file"; }; zone "hangulcafes.ga" { type master; notify no; file "null.zone.file"; }; zone "hanh.cz" { type master; notify no; file "null.zone.file"; }; -zone "hanhtrinhtamlinh.com" { type master; notify no; file "null.zone.file"; }; zone "hanhtrinhthanhnienkhoinghiep.vn" { type master; notify no; file "null.zone.file"; }; zone "haniamarket.com" { type master; notify no; file "null.zone.file"; }; zone "hanict.org.vn" { type master; notify no; file "null.zone.file"; }; @@ -40498,7 +40494,6 @@ zone "harrisburgprinting.com" { type master; notify no; file "null.zone.file"; } zone "harriscustomcatering.com" { type master; notify no; file "null.zone.file"; }; zone "harrisheatpumps.nz" { type master; notify no; file "null.zone.file"; }; zone "harrisnewtech.ir" { type master; notify no; file "null.zone.file"; }; -zone "harrisoncarter.com" { type master; notify no; file "null.zone.file"; }; zone "harrisonlily.co.uk" { type master; notify no; file "null.zone.file"; }; zone "harryfang.com" { type master; notify no; file "null.zone.file"; }; zone "harryhiggins.com" { type master; notify no; file "null.zone.file"; }; @@ -43299,7 +43294,6 @@ zone "i-sharecloud.com" { type master; notify no; file "null.zone.file"; }; zone "i-supportcharity.com" { type master; notify no; file "null.zone.file"; }; zone "i-vnsweyu.pl" { type master; notify no; file "null.zone.file"; }; zone "i-voda.com" { type master; notify no; file "null.zone.file"; }; -zone "i.fiery.me" { type master; notify no; file "null.zone.file"; }; zone "i.fluffy.cc" { type master; notify no; file "null.zone.file"; }; zone "i.funtourspt.eu" { type master; notify no; file "null.zone.file"; }; zone "i.ooxx.ooo" { type master; notify no; file "null.zone.file"; }; @@ -49680,6 +49674,7 @@ zone "kebunrayabaturraden.id" { type master; notify no; file "null.zone.file"; } zone "kec-cendana.enrekangkab.go.id" { type master; notify no; file "null.zone.file"; }; zone "kec-wlingi.blitarkab.go.id" { type master; notify no; file "null.zone.file"; }; zone "kecforging.com" { type master; notify no; file "null.zone.file"; }; +zone "kechuahangdidong.com" { type master; notify no; file "null.zone.file"; }; zone "keciorenkoltukyikama.net" { type master; notify no; file "null.zone.file"; }; zone "keckarangdadap.pekalongankab.go.id" { type master; notify no; file "null.zone.file"; }; zone "kecsfila.hu" { type master; notify no; file "null.zone.file"; }; @@ -67483,6 +67478,7 @@ zone "osrsport.com" { type master; notify no; file "null.zone.file"; }; zone "ossandonycia.cl" { type master; notify no; file "null.zone.file"; }; zone "osscaar.com" { type master; notify no; file "null.zone.file"; }; zone "osservatore.betacom.it" { type master; notify no; file "null.zone.file"; }; +zone "ossi4.51cto.com" { type master; notify no; file "null.zone.file"; }; zone "ossianlaw.com" { type master; notify no; file "null.zone.file"; }; zone "osslusturv.com" { type master; notify no; file "null.zone.file"; }; zone "ossoriobouliz.com" { type master; notify no; file "null.zone.file"; }; @@ -70815,6 +70811,7 @@ zone "politinsky.000webhostapp.com" { type master; notify no; file "null.zone.fi zone "politrix.net" { type master; notify no; file "null.zone.file"; }; zone "poliyzsl.host" { type master; notify no; file "null.zone.file"; }; zone "poljimenez.com" { type master; notify no; file "null.zone.file"; }; +zone "polk.k12.ga.us" { type master; notify no; file "null.zone.file"; }; zone "polka32.ru" { type master; notify no; file "null.zone.file"; }; zone "polkapower.com" { type master; notify no; file "null.zone.file"; }; zone "polkolonieb4k.pl" { type master; notify no; file "null.zone.file"; }; @@ -71986,7 +71983,6 @@ zone "professionalshop.in" { type master; notify no; file "null.zone.file"; }; zone "professionalwaiterskollege.org" { type master; notify no; file "null.zone.file"; }; zone "professionelelit.com" { type master; notify no; file "null.zone.file"; }; zone "professorsgallery.com" { type master; notify no; file "null.zone.file"; }; -zone "profetestruec.net" { type master; notify no; file "null.zone.file"; }; zone "profexsystem.com" { type master; notify no; file "null.zone.file"; }; zone "proffessia.ru" { type master; notify no; file "null.zone.file"; }; zone "proffice.com.pl" { type master; notify no; file "null.zone.file"; }; @@ -72364,6 +72360,7 @@ zone "protech.binarybizz.com" { type master; notify no; file "null.zone.file"; } zone "protech.mn" { type master; notify no; file "null.zone.file"; }; zone "protechcarpetcare.com" { type master; notify no; file "null.zone.file"; }; zone "protechgroup1.com" { type master; notify no; file "null.zone.file"; }; +zone "protect.mimecast-offshore.com" { type master; notify no; file "null.zone.file"; }; zone "protectiadatelor.biz" { type master; notify no; file "null.zone.file"; }; zone "protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org" { type master; notify no; file "null.zone.file"; }; zone "protection.pecol.eu" { type master; notify no; file "null.zone.file"; }; @@ -80470,7 +80467,6 @@ zone "shareallfilesthroughsecureexchangesystem.duckdns.org" { type master; notif zone "sharebook.tk" { type master; notify no; file "null.zone.file"; }; zone "sharechautari.com" { type master; notify no; file "null.zone.file"; }; zone "shared-cnd.com" { type master; notify no; file "null.zone.file"; }; -zone "shared.pdffiller.com" { type master; notify no; file "null.zone.file"; }; zone "shareddocuments.ml" { type master; notify no; file "null.zone.file"; }; zone "shareddynamics.com" { type master; notify no; file "null.zone.file"; }; zone "sharedeconomy.eu" { type master; notify no; file "null.zone.file"; }; @@ -86099,6 +86095,7 @@ zone "sup3rc10ud.ga" { type master; notify no; file "null.zone.file"; }; zone "supadom.fr" { type master; notify no; file "null.zone.file"; }; zone "supamidland-my.sharepoint.com" { type master; notify no; file "null.zone.file"; }; zone "supcargo.com" { type master; notify no; file "null.zone.file"; }; +zone "supdate.mediaweb.co.kr" { type master; notify no; file "null.zone.file"; }; zone "super-filtr.ru" { type master; notify no; file "null.zone.file"; }; zone "super-gamezer.com" { type master; notify no; file "null.zone.file"; }; zone "super-industries.co" { type master; notify no; file "null.zone.file"; }; @@ -90717,7 +90714,6 @@ zone "tlcmoto.com" { type master; notify no; file "null.zone.file"; }; zone "tldrbox.top" { type master; notify no; file "null.zone.file"; }; zone "tlextreme.com" { type master; notify no; file "null.zone.file"; }; zone "tlfthelifefactory.com.au" { type master; notify no; file "null.zone.file"; }; -zone "tlgur.com" { type master; notify no; file "null.zone.file"; }; zone "tlkcloudem.com" { type master; notify no; file "null.zone.file"; }; zone "tlktdsfj.sha58.me" { type master; notify no; file "null.zone.file"; }; zone "tlpclient.site" { type master; notify no; file "null.zone.file"; }; @@ -92353,6 +92349,7 @@ zone "tsport88.com" { type master; notify no; file "null.zone.file"; }; zone "tsr-mark.xyz" { type master; notify no; file "null.zone.file"; }; zone "tsredco.telangana.gov.in" { type master; notify no; file "null.zone.file"; }; zone "tsrj.monster" { type master; notify no; file "null.zone.file"; }; +zone "tsrv2.top" { type master; notify no; file "null.zone.file"; }; zone "tst.marineindust.com" { type master; notify no; file "null.zone.file"; }; zone "tstfrigo.com" { type master; notify no; file "null.zone.file"; }; zone "tsugite.youbi.me" { type master; notify no; file "null.zone.file"; }; @@ -93764,6 +93761,7 @@ zone "update-chase.justmoveup.com" { type master; notify no; file "null.zone.fil zone "update-prog.com" { type master; notify no; file "null.zone.file"; }; zone "update-res.100public.com" { type master; notify no; file "null.zone.file"; }; zone "update.5v.pl" { type master; notify no; file "null.zone.file"; }; +zone "update.7h4uk.com" { type master; notify no; file "null.zone.file"; }; zone "update.att.tools" { type master; notify no; file "null.zone.file"; }; zone "update.bracncet.net" { type master; notify no; file "null.zone.file"; }; zone "update.bruss.org.ru" { type master; notify no; file "null.zone.file"; }; @@ -94003,6 +94001,7 @@ zone "url-update.com" { type master; notify no; file "null.zone.file"; }; zone "url-validation-clients.com" { type master; notify no; file "null.zone.file"; }; zone "url.246546.com" { type master; notify no; file "null.zone.file"; }; zone "url.57569.fr.snd52.ch" { type master; notify no; file "null.zone.file"; }; +zone "url2.mailanyone.net" { type master; notify no; file "null.zone.file"; }; zone "url3.mailanyone.net" { type master; notify no; file "null.zone.file"; }; zone "url5459.41southbar.com" { type master; notify no; file "null.zone.file"; }; zone "url675.textilmallorca.com" { type master; notify no; file "null.zone.file"; }; @@ -95401,7 +95400,6 @@ zone "viettrungkhaison.com" { type master; notify no; file "null.zone.file"; }; zone "viettrust-vn.net" { type master; notify no; file "null.zone.file"; }; zone "vietucgroup.org" { type master; notify no; file "null.zone.file"; }; zone "vietup.net" { type master; notify no; file "null.zone.file"; }; -zone "vietvictory.vn" { type master; notify no; file "null.zone.file"; }; zone "vievioparapija.eu" { type master; notify no; file "null.zone.file"; }; zone "view-indonesia.com" { type master; notify no; file "null.zone.file"; }; zone "view-your-website.com" { type master; notify no; file "null.zone.file"; }; @@ -95855,6 +95853,7 @@ zone "visual-sounds.com" { type master; notify no; file "null.zone.file"; }; zone "visualblends.com" { type master; notify no; file "null.zone.file"; }; zone "visualdata.ru" { type master; notify no; file "null.zone.file"; }; zone "visualdimensioniq.com" { type master; notify no; file "null.zone.file"; }; +zone "visualdive.com" { type master; notify no; file "null.zone.file"; }; zone "visualendodontics.net" { type master; notify no; file "null.zone.file"; }; zone "visualgag.co.uk" { type master; notify no; file "null.zone.file"; }; zone "visualhome.cl" { type master; notify no; file "null.zone.file"; }; @@ -96933,7 +96932,6 @@ zone "wc2018.top" { type master; notify no; file "null.zone.file"; }; zone "wc3prince.ru" { type master; notify no; file "null.zone.file"; }; zone "wcare.nl" { type master; notify no; file "null.zone.file"; }; zone "wcbgroup.co.uk" { type master; notify no; file "null.zone.file"; }; -zone "wcdownloadercdn.lavasoft.com" { type master; notify no; file "null.zone.file"; }; zone "wcdr.pbas.es" { type master; notify no; file "null.zone.file"; }; zone "wcf-old.sibcat.info" { type master; notify no; file "null.zone.file"; }; zone "wcfamlaw.com" { type master; notify no; file "null.zone.file"; }; @@ -98599,6 +98597,7 @@ zone "workingin-my.sharepoint.com" { type master; notify no; file "null.zone.fil zone "workingonit.site" { type master; notify no; file "null.zone.file"; }; zone "workingpainters.com" { type master; notify no; file "null.zone.file"; }; zone "workingroofers.com" { type master; notify no; file "null.zone.file"; }; +zone "workingsolutionsrome.org" { type master; notify no; file "null.zone.file"; }; zone "workingwell.club" { type master; notify no; file "null.zone.file"; }; zone "worklinic.com.br" { type master; notify no; file "null.zone.file"; }; zone "workmate-sien.com" { type master; notify no; file "null.zone.file"; }; @@ -100965,7 +100964,6 @@ zone "yoyoplease.com" { type master; notify no; file "null.zone.file"; }; zone "yoyoso.nz" { type master; notify no; file "null.zone.file"; }; zone "yoyoteacher.cn" { type master; notify no; file "null.zone.file"; }; zone "yp.dcyazilim.com" { type master; notify no; file "null.zone.file"; }; -zone "yp.hnggzyjy.cn" { type master; notify no; file "null.zone.file"; }; zone "ypbb.or.id" { type master; notify no; file "null.zone.file"; }; zone "ypddf.org" { type master; notify no; file "null.zone.file"; }; zone "ypicsdy.cf" { type master; notify no; file "null.zone.file"; }; @@ -101914,6 +101912,7 @@ zone "zoovetdv.ru" { type master; notify no; file "null.zone.file"; }; zone "zoox.com.br" { type master; notify no; file "null.zone.file"; }; zone "zoparo.nl" { type master; notify no; file "null.zone.file"; }; zone "zopbxtjiuykhyyp.usa.cc" { type master; notify no; file "null.zone.file"; }; +zone "zopro.duckdns.org" { type master; notify no; file "null.zone.file"; }; zone "zoracle.com" { type master; notify no; file "null.zone.file"; }; zone "zorancreative.com" { type master; notify no; file "null.zone.file"; }; zone "zoratech.ro" { type master; notify no; file "null.zone.file"; }; diff --git a/urlhaus-filter-dnsmasq-online.conf b/urlhaus-filter-dnsmasq-online.conf index 82908cce..0d0f6b2f 100644 --- a/urlhaus-filter-dnsmasq-online.conf +++ b/urlhaus-filter-dnsmasq-online.conf @@ -1,5 +1,5 @@ # Title: Online Malicious Domains dnsmasq Blocklist -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -16,7 +16,6 @@ address=/360.lcy2zzx.pw/0.0.0.0 address=/360down7.miiyun.cn/0.0.0.0 address=/77st.net/0.0.0.0 address=/8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com/0.0.0.0 -address=/87du.vip/0.0.0.0 address=/8poieq.bn.files.1drv.com/0.0.0.0 address=/aatreefelling.co.za/0.0.0.0 address=/abad.tv/0.0.0.0 @@ -77,6 +76,7 @@ address=/anadelgbt.org/0.0.0.0 address=/anantam.net.in/0.0.0.0 address=/andreelapeyre.com/0.0.0.0 address=/andremaraisbeleggings.co.za/0.0.0.0 +address=/andreonemaia.com/0.0.0.0 address=/andres.ac.ug/0.0.0.0 address=/andres.ug/0.0.0.0 address=/andreshconcejal.solucioneslink.com/0.0.0.0 @@ -86,7 +86,6 @@ address=/angloteste.bigprime.com.br/0.0.0.0 address=/anhung1102.vn/0.0.0.0 address=/anurontv.com/0.0.0.0 address=/anysbergbiltong.co.za/0.0.0.0 -address=/apartamentoscitta.com/0.0.0.0 address=/api-ms.cobainaja.id/0.0.0.0 address=/api.cstdevs.com/0.0.0.0 address=/api.quocbao.biz/0.0.0.0 @@ -109,15 +108,17 @@ address=/atlasconcreteworks.com/0.0.0.0 address=/attach.66rpg.com/0.0.0.0 address=/atteuqpotentialunlimited.com/0.0.0.0 address=/augustair.com/0.0.0.0 +address=/aulist.com/0.0.0.0 +address=/automaticrefreshments.com/0.0.0.0 address=/avadhanagames.com/0.0.0.0 address=/ayahuascasp.com.br/0.0.0.0 address=/ayamallah.com/0.0.0.0 +address=/aycconsultoriaempresarial.com/0.0.0.0 address=/azmeasurement.com/0.0.0.0 address=/b2b.toptanakaryakit.com.tr/0.0.0.0 address=/backgrounds.pk/0.0.0.0 address=/badeggdesign.com/0.0.0.0 address=/balealgodon.mx/0.0.0.0 -address=/ballina.andrewmaughan.com/0.0.0.0 address=/bangkok-orchids.com/0.0.0.0 address=/bangladeshunbound.com/0.0.0.0 address=/bary.sz4h.com/0.0.0.0 @@ -128,6 +129,7 @@ address=/bbia.co.uk/0.0.0.0 address=/bcmt.elin.co.za/0.0.0.0 address=/bcrg.co.za/0.0.0.0 address=/bdnextrend.xyz/0.0.0.0 +address=/beanx88.xyz/0.0.0.0 address=/bearcatpumps.com.cn/0.0.0.0 address=/beautincollagen.rs/0.0.0.0 address=/bekape.co.id/0.0.0.0 @@ -135,6 +137,7 @@ address=/beor360.com/0.0.0.0 address=/bespokeweddings.ie/0.0.0.0 address=/bestcarenepal.com/0.0.0.0 address=/betone.co.kr/0.0.0.0 +address=/betycopaints.com/0.0.0.0 address=/beveragesmiami.solucioneslink.com/0.0.0.0 address=/bhavaniengineering.com/0.0.0.0 address=/bigmikesupplies.co.za/0.0.0.0 @@ -163,6 +166,7 @@ address=/bophelocare.co.za/0.0.0.0 address=/bounces.mi-fs.com/0.0.0.0 address=/boutiqueofferte.com/0.0.0.0 address=/bpo.correct.go.th/0.0.0.0 +address=/bradleyinstitute.co.za/0.0.0.0 address=/brandtrust.com.pk/0.0.0.0 address=/braunfinancial.com.au/0.0.0.0 address=/brendanquine.com/0.0.0.0 @@ -213,6 +217,7 @@ address=/chezalice.co.za/0.0.0.0 address=/childselect.com/0.0.0.0 address=/chinhdropfile.myvnc.com/0.0.0.0 address=/chinhdropfile80.myvnc.com/0.0.0.0 +address=/chipmania.it/0.0.0.0 address=/cible-energy.com/0.0.0.0 address=/cifeer.net/0.0.0.0 address=/cirugiadenarizbucaramanga.com/0.0.0.0 @@ -226,10 +231,9 @@ address=/cloud.fc.co.mz/0.0.0.0 address=/cm-arquitetos.com/0.0.0.0 address=/codsambal.com/0.0.0.0 address=/colempaques.info/0.0.0.0 -address=/colinde.pricesne.com/0.0.0.0 address=/colorpak.pl/0.0.0.0 +address=/columbia.aula-web.net/0.0.0.0 address=/community.reimclub.com/0.0.0.0 -address=/comosairdoburaco.com.br/0.0.0.0 address=/competancy.indigoconsult.net/0.0.0.0 address=/conceptimagine.ro/0.0.0.0 address=/config.cqhbkjzx.com/0.0.0.0 @@ -245,7 +249,6 @@ address=/covid19.cyberschool.or.id/0.0.0.0 address=/cpanel.shivay.net/0.0.0.0 address=/cr-sq.com/0.0.0.0 address=/craftech.nxtnet.ga/0.0.0.0 -address=/crearechile.cl/0.0.0.0 address=/creationskateboards.com/0.0.0.0 address=/crecerco.com/0.0.0.0 address=/crittersbythebay.com/0.0.0.0 @@ -255,7 +258,6 @@ address=/crmroche.manivelasst.com/0.0.0.0 address=/crscorretordeimoveis.com.br/0.0.0.0 address=/cse-engineer.com/0.0.0.0 address=/csnserver.com/0.0.0.0 -address=/ctracknxt.in/0.0.0.0 address=/cubescargoexpress.com/0.0.0.0 address=/curasoles.co.za/0.0.0.0 address=/currantmedia.com/0.0.0.0 @@ -274,7 +276,6 @@ address=/data.cdevelop.org/0.0.0.0 address=/data.over-blog-kiwi.com/0.0.0.0 address=/datapolish.com/0.0.0.0 address=/dating.khokhas.co.za/0.0.0.0 -address=/datsom.vn/0.0.0.0 address=/davethompson.me.uk/0.0.0.0 address=/davidmcguinness.info/0.0.0.0 address=/dayspringdaisies.com/0.0.0.0 @@ -298,7 +299,6 @@ address=/destinymc.co.za/0.0.0.0 address=/detorre.es/0.0.0.0 address=/dev.sebpo.net/0.0.0.0 address=/dev.watch-store.eu/0.0.0.0 -address=/dezcom.com/0.0.0.0 address=/dfcf.91756.cn/0.0.0.0 address=/dfsfcsfcdsfsdvcfsvcscv.com/0.0.0.0 address=/diamantenegro.mi-fs.com/0.0.0.0 @@ -313,6 +313,7 @@ address=/dl.installcdn-aws.com/0.0.0.0 address=/dl.packetstormsecurity.net/0.0.0.0 address=/dl.rina-roleplay.com/0.0.0.0 address=/dnn.alibuf.com/0.0.0.0 +address=/dns.alibuf.com/0.0.0.0 address=/dns.cyberium.cc/0.0.0.0 address=/dockerupdate.anondns.net/0.0.0.0 address=/docman.orientalservices.in/0.0.0.0 @@ -329,6 +330,8 @@ address=/dosame.com/0.0.0.0 address=/dosman.pl/0.0.0.0 address=/dovberger.com/0.0.0.0 address=/down.pcclear.com/0.0.0.0 +address=/down.postch-de.top/0.0.0.0 +address=/down.postch-dl.top/0.0.0.0 address=/down.udashi.com/0.0.0.0 address=/down.webbora.com/0.0.0.0 address=/down1.arpun.com/0.0.0.0 @@ -388,14 +391,13 @@ address=/extrovertoffers.com/0.0.0.0 address=/f1sol.com/0.0.0.0 address=/fahrzeugdrive.com/0.0.0.0 address=/familydentist.site/0.0.0.0 -address=/faveraprojects.com/0.0.0.0 address=/fc.co.mz/0.0.0.0 address=/felicienne.nl/0.0.0.0 address=/files.martellexpress.us/0.0.0.0 address=/filmotainment.com/0.0.0.0 address=/final.makkahkmcc.com/0.0.0.0 address=/fineartgallerym.com/0.0.0.0 -address=/fisconline.casa/0.0.0.0 +address=/fisconline.bar/0.0.0.0 address=/fix-america-now.org/0.0.0.0 address=/fixauto.illumetechnology.com/0.0.0.0 address=/fixturegovernment.com/0.0.0.0 @@ -410,7 +412,6 @@ address=/foothills.com.br/0.0.0.0 address=/footweardirect.elin.co.za/0.0.0.0 address=/forum.mdb.nu/0.0.0.0 address=/fotoobjetivo.com/0.0.0.0 -address=/foundationrepairhoustontx.net/0.0.0.0 address=/foxeps.com.br/0.0.0.0 address=/fraud.bpcbankingtech.com/0.0.0.0 address=/freecnetdownload.com/0.0.0.0 @@ -419,7 +420,6 @@ address=/ftp.n3twork30cm.ml/0.0.0.0 address=/fullelectronica.com.ar/0.0.0.0 address=/funletters.net/0.0.0.0 address=/fusionfiresolutions.com/0.0.0.0 -address=/futbolpr.com/0.0.0.0 address=/futuregraphics.com.ar/0.0.0.0 address=/g.pinmonkey.xyz/0.0.0.0 address=/gametwogame.com/0.0.0.0 @@ -436,6 +436,7 @@ address=/ghettohub.co.za/0.0.0.0 address=/ghislain.dartois.pagesperso-orange.fr/0.0.0.0 address=/giadungg7.com/0.0.0.0 address=/giddos.ga/0.0.0.0 +address=/giteletropical.com/0.0.0.0 address=/glowinmedia.co.ke/0.0.0.0 address=/gmsebpl.com/0.0.0.0 address=/gmtransformationacademy.com/0.0.0.0 @@ -448,6 +449,7 @@ address=/goldcoastoffice365.com/0.0.0.0 address=/goldcoastoffice365.com.au/0.0.0.0 address=/golden-memories-funerals.yourpageserver.com/0.0.0.0 address=/goldenasiacapital.com/0.0.0.0 +address=/goldmen.in/0.0.0.0 address=/gorecycle.fahadjutt.com/0.0.0.0 address=/gpotecnosystems.com/0.0.0.0 address=/gracejukes.com/0.0.0.0 @@ -476,13 +478,12 @@ address=/hhaward.org/0.0.0.0 address=/highlandroadcoc.com/0.0.0.0 address=/highlandslasvegas.atakdev.com/0.0.0.0 address=/hindi.factsriver.com/0.0.0.0 -address=/hiptool.net/0.0.0.0 address=/hitpe.com/0.0.0.0 address=/hitstation.nl/0.0.0.0 +address=/hlmd.in/0.0.0.0 address=/hmpmall.co.kr/0.0.0.0 address=/hoagietesting10.com/0.0.0.0 address=/hoayeuthuong-my.sharepoint.com/0.0.0.0 -address=/holmesservices.mobiledevsite.co/0.0.0.0 address=/homefindersolutions.com/0.0.0.0 address=/hongluosi.com/0.0.0.0 address=/hookedupboatclub.com/0.0.0.0 @@ -493,7 +494,6 @@ address=/houstonshutters.site/0.0.0.0 address=/hr2019.vrcom7.com/0.0.0.0 address=/hrnautica.com.br/0.0.0.0 address=/hseda.com/0.0.0.0 -address=/hsmwebapp.com/0.0.0.0 address=/htownbars.com/0.0.0.0 address=/hubtech.co.za/0.0.0.0 address=/huellacero.cl/0.0.0.0 @@ -533,16 +533,19 @@ address=/ioabc.wif.com.br/0.0.0.0 address=/ipmes.ma/0.0.0.0 address=/iremart.es/0.0.0.0 address=/iris101.co.uk/0.0.0.0 +address=/isaac.mikhailmotoringschool.com/0.0.0.0 address=/iscamenabe.com/0.0.0.0 address=/isiphephelocon.co.za/0.0.0.0 address=/iso-dubai.net/0.0.0.0 address=/israrulhaq.me/0.0.0.0 +address=/isrorg.com/0.0.0.0 address=/isso.ps/0.0.0.0 address=/ist-security.com/0.0.0.0 address=/it123.ru/0.0.0.0 address=/italiandirezione.casa/0.0.0.0 address=/itc-demo.softgig.co.ke/0.0.0.0 address=/itelsys.ma/0.0.0.0 +address=/itmotasaciones.com/0.0.0.0 address=/jacktech.jackindia.com/0.0.0.0 address=/jaishritours.com/0.0.0.0 address=/jamiekaylive.com/0.0.0.0 @@ -556,6 +559,7 @@ address=/jennwolfemtb.com/0.0.0.0 address=/jhayesconsulting.com/0.0.0.0 address=/jiaoyuzixun.cn/0.0.0.0 address=/jing-da.com.tw/0.0.0.0 +address=/jmtc.91756.cn/0.0.0.0 address=/jnanbharati.com/0.0.0.0 address=/jobs.thebeessolution.com/0.0.0.0 address=/joelbonissilver.com/0.0.0.0 @@ -566,6 +570,7 @@ address=/jumpmanualjacobhiller.com/0.0.0.0 address=/jupiter.toxsl.in/0.0.0.0 address=/justinscott.com.au/0.0.0.0 address=/kadigital.co.uk/0.0.0.0 +address=/kaizenjanitorial.com/0.0.0.0 address=/kalawatihomes.com/0.0.0.0 address=/kalogirosfinance.com/0.0.0.0 address=/kaptaanchapal.com/0.0.0.0 @@ -627,14 +632,16 @@ address=/lotusanddragonfly.com/0.0.0.0 address=/lp.definerisco.com/0.0.0.0 address=/lp.difusodesign.com/0.0.0.0 address=/lp.quama.pe/0.0.0.0 -address=/ltc.typoten.com/0.0.0.0 +address=/luckybrownie.com/0.0.0.0 address=/luminouspneuma.com/0.0.0.0 address=/luxomodels.com/0.0.0.0 address=/m-technics.kz/0.0.0.0 address=/m.estudiomoros.com.ar/0.0.0.0 address=/m.mobilelocalsales.com/0.0.0.0 +address=/m.softsharks.com/0.0.0.0 address=/madicon.co.za/0.0.0.0 address=/magianegramagiablancayamarres.com/0.0.0.0 +address=/maharaniworld.com/0.0.0.0 address=/mail.bs-eiendomme.co.za/0.0.0.0 address=/mail.golimoapp.com/0.0.0.0 address=/mail.jeffsono.org/0.0.0.0 @@ -660,7 +667,6 @@ address=/matruchhaya.co.in/0.0.0.0 address=/maxiquim.cl/0.0.0.0 address=/maxoprint.co.uk/0.0.0.0 address=/maxtox.com.pk/0.0.0.0 -address=/maybethescobar.com/0.0.0.0 address=/mbgrm.com/0.0.0.0 address=/mbjtimes.com/0.0.0.0 address=/mbsolutions.ge/0.0.0.0 @@ -691,11 +697,12 @@ address=/michaelphilip.com/0.0.0.0 address=/michimal2.000webhostapp.com/0.0.0.0 address=/microblading.mirliandias.com.br/0.0.0.0 address=/microcomm-group.com/0.0.0.0 +address=/mikhailmotoringschool.com/0.0.0.0 +address=/mills-skyla30ec.com/0.0.0.0 address=/mingguanwms.com/0.0.0.0 address=/minuevavida.org/0.0.0.0 address=/mirror.mypage.sk/0.0.0.0 address=/misterson.com/0.0.0.0 -address=/mixr.at/0.0.0.0 address=/mkontakt.az/0.0.0.0 address=/mktf.mx/0.0.0.0 address=/mmdx.com/0.0.0.0 @@ -732,6 +739,7 @@ address=/navayurveda.in/0.0.0.0 address=/nec-i.com/0.0.0.0 address=/nedkellymyanmar.com/0.0.0.0 address=/nelitrianggraeni.000webhostapp.com/0.0.0.0 +address=/nellaimasthanbiryani.com/0.0.0.0 address=/nerve.untergrund.net/0.0.0.0 address=/nettube.com.br/0.0.0.0 address=/networkwheels.co.za/0.0.0.0 @@ -756,7 +764,6 @@ address=/njtiledesigncenter.com/0.0.0.0 address=/nobius.org/0.0.0.0 address=/nocalnoodle.elin.co.za/0.0.0.0 address=/nomadicbees.com/0.0.0.0 -address=/nonnarina.ax/0.0.0.0 address=/notamuzikaletleri.com/0.0.0.0 address=/ns1.the-widyantos.com/0.0.0.0 address=/nsb.org.uk/0.0.0.0 @@ -776,12 +783,15 @@ address=/omaromatic.com/0.0.0.0 address=/omega.az/0.0.0.0 address=/oms.pappai.com/0.0.0.0 address=/omscoc.pappai.com/0.0.0.0 +address=/onedigitalcard.granvizionnecorp.com/0.0.0.0 address=/onedrive.listifyapp.co/0.0.0.0 address=/online.creedglobal.in/0.0.0.0 address=/onlinestatis.bar/0.0.0.0 +address=/open.rawntech.com/0.0.0.0 address=/open.warehousesaas.co.uk/0.0.0.0 address=/opentoronto.org/0.0.0.0 address=/opolis.io/0.0.0.0 +address=/opticaoptigral.cl/0.0.0.0 address=/optimus.com.sg/0.0.0.0 address=/order.bizpeed.com/0.0.0.0 address=/orientgatewayltd.com/0.0.0.0 @@ -819,6 +829,7 @@ address=/pcsoori.com/0.0.0.0 address=/pd.oceaniarp.net/0.0.0.0 address=/pemdodo.com/0.0.0.0 address=/perfumeriamontes.es/0.0.0.0 +address=/periodiche.bar/0.0.0.0 address=/perpus.onlineman7-jombang.sch.id/0.0.0.0 address=/perpustekim.untirta.ac.id/0.0.0.0 address=/pestoclean.co.uk/0.0.0.0 @@ -838,6 +849,7 @@ address=/pmglance.startwriteup.com/0.0.0.0 address=/pointactionsg.com/0.0.0.0 address=/pokojewewladyslawowie.pl/0.0.0.0 address=/pole.com.vc/0.0.0.0 +address=/ponchokhana.com/0.0.0.0 address=/pool.phxdir.com/0.0.0.0 address=/pooltablemoversdenver.net/0.0.0.0 address=/portal.premiumpunch.com/0.0.0.0 @@ -848,6 +860,7 @@ address=/prestasicash.com.ar/0.0.0.0 address=/prestigehomeautomation.net/0.0.0.0 address=/preview2.behalen.com/0.0.0.0 address=/prishaartcreations.com/0.0.0.0 +address=/prismaxis.com/0.0.0.0 address=/production.sparshims.com/0.0.0.0 address=/programaoperadoronline.com.br/0.0.0.0 address=/project.exquitec.com/0.0.0.0 @@ -899,7 +912,6 @@ address=/reseller.itechbrasil.com/0.0.0.0 address=/resuco.net/0.0.0.0 address=/rezkabum.ru/0.0.0.0 address=/rhema.com.sg/0.0.0.0 -address=/richancyber.info/0.0.0.0 address=/richmondminerals.co.zm/0.0.0.0 address=/rinaefoundation.org.za/0.0.0.0 address=/rinkaisystem-ht.com/0.0.0.0 @@ -908,7 +920,6 @@ address=/rkcable.co.in/0.0.0.0 address=/rkverify.securestudies.com/0.0.0.0 address=/robertmcardle.com/0.0.0.0 address=/robertsinclair.net/0.0.0.0 -address=/romanianpoints.com/0.0.0.0 address=/ronnietucker.co.uk/0.0.0.0 address=/roomsvc.servegate.kr/0.0.0.0 address=/roshnijewellery.com/0.0.0.0 @@ -918,7 +929,6 @@ address=/rubycityvietnam.com/0.0.0.0 address=/ruisgood.ru/0.0.0.0 address=/ruwadalkuwait.com/0.0.0.0 address=/rydchile.cl/0.0.0.0 -address=/s.51shijuan.com/0.0.0.0 address=/s.thechinesemuslim.com/0.0.0.0 address=/sac2.11xii.com/0.0.0.0 address=/sacredscentsonline.com/0.0.0.0 @@ -952,7 +962,9 @@ address=/serendibsourcing.com/0.0.0.0 address=/sericaasia.com/0.0.0.0 address=/servicemhkd.myvnc.com/0.0.0.0 address=/servicemhkd80.myvnc.com/0.0.0.0 +address=/serviciovirtual.com.ar/0.0.0.0 address=/sexologistpakistan.net/0.0.0.0 +address=/seyranikenger.com.tr/0.0.0.0 address=/sgb.ac.ke/0.0.0.0 address=/sgessy.com.br/0.0.0.0 address=/shaheentbfoundation.com/0.0.0.0 @@ -1003,6 +1015,7 @@ address=/spaceframe.mobi.space-frame.co.za/0.0.0.0 address=/special-key.cf/0.0.0.0 address=/spent.com.pl/0.0.0.0 address=/spetsesyachtcharter.gr/0.0.0.0 +address=/spiritualroot.org/0.0.0.0 address=/spititourism.com/0.0.0.0 address=/spittinfire.com/0.0.0.0 address=/sports-net.de/0.0.0.0 @@ -1022,7 +1035,7 @@ address=/stiepancasetia.ac.id/0.0.0.0 address=/stlukesohag.com/0.0.0.0 address=/store.ericalgarin.com/0.0.0.0 address=/stott-thompson.co.uk/0.0.0.0 -address=/streetdemo.yourpageserver.com/0.0.0.0 +address=/stratexec.co.za/0.0.0.0 address=/suboldesign.com/0.0.0.0 address=/sumerians.org/0.0.0.0 address=/sunaryem.com.tr/0.0.0.0 @@ -1070,6 +1083,7 @@ address=/test.lubrico.in/0.0.0.0 address=/test.typoten.com/0.0.0.0 address=/test.wanepghana.org/0.0.0.0 address=/test1.asistencia247.com/0.0.0.0 +address=/test1.milenial.id/0.0.0.0 address=/test1.tenplusone.my/0.0.0.0 address=/test2.basis-web.com/0.0.0.0 address=/test2.marrenconstruction.ie/0.0.0.0 @@ -1094,7 +1108,7 @@ address=/themansionkasauli.com/0.0.0.0 address=/theprofinn.com/0.0.0.0 address=/thesummitpc.net/0.0.0.0 address=/theurbantutors.com/0.0.0.0 -address=/thientu.net/0.0.0.0 +address=/thirdstringcalifornia.com/0.0.0.0 address=/thosewebbs.com/0.0.0.0 address=/thriveink.com/0.0.0.0 address=/tianangdep.com/0.0.0.0 @@ -1104,7 +1118,6 @@ address=/timamollo.co.za/0.0.0.0 address=/timegonebuy.com/0.0.0.0 address=/tksb.net/0.0.0.0 address=/tlcc.com.gt/0.0.0.0 -address=/tntmedia.gr/0.0.0.0 address=/todoapp.cstdevs.com/0.0.0.0 address=/todocontodo.com.mx/0.0.0.0 address=/tonydong.com/0.0.0.0 @@ -1141,6 +1154,7 @@ address=/ultimate-24.de/0.0.0.0 address=/umwelt-kirchhof.de/0.0.0.0 address=/unicorpbrunei.com/0.0.0.0 address=/uniengrisb.com/0.0.0.0 +address=/unisoftcc.com/0.0.0.0 address=/unyazitelecom.com/0.0.0.0 address=/upcbpta.com/0.0.0.0 address=/urbantrapfest.cl/0.0.0.0 @@ -1155,7 +1169,9 @@ address=/vbcargo.hu/0.0.0.0 address=/vcah.co.uk/0.0.0.0 address=/vectarts.com/0.0.0.0 address=/vegadelcasero.cl/0.0.0.0 +address=/velma-harber30ku.com/0.0.0.0 address=/vendas.lidiacarmeli.com.br/0.0.0.0 +address=/versualstudio.com/0.0.0.0 address=/veterinariadrpopui.com/0.0.0.0 address=/vfocus.net/0.0.0.0 address=/vienen.gblix.srv.br/0.0.0.0 @@ -1182,6 +1198,7 @@ address=/vvsskmodinationalschool.com/0.0.0.0 address=/w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu/0.0.0.0 address=/wanepliberia.org/0.0.0.0 address=/wanepniger.org/0.0.0.0 +address=/weareactum.com/0.0.0.0 address=/web.eng.ubu.ac.th/0.0.0.0 address=/web.geetle.ga/0.0.0.0 address=/web.geomegasoft.net/0.0.0.0 @@ -1209,6 +1226,7 @@ address=/wolfgang-brodte.de/0.0.0.0 address=/wonderhawaii.com/0.0.0.0 address=/woodsytech.com/0.0.0.0 address=/wordpress.saleensuporte.com.br/0.0.0.0 +address=/workingsolutionsrome.org/0.0.0.0 address=/wozata.000webhostapp.com/0.0.0.0 address=/wp.readhere.in/0.0.0.0 address=/wpdemo.101clients.com.au/0.0.0.0 @@ -1230,7 +1248,6 @@ address=/yoast.yourpageserver.com/0.0.0.0 address=/yourclub1.com/0.0.0.0 address=/yourtopdog.com.au/0.0.0.0 address=/youtubetrainingacademy.com/0.0.0.0 -address=/yp.hnggzyjy.cn/0.0.0.0 address=/yskadvisors.com/0.0.0.0 address=/yummyyogaudaipur.com/0.0.0.0 address=/yzkzixun.com/0.0.0.0 diff --git a/urlhaus-filter-dnsmasq.conf b/urlhaus-filter-dnsmasq.conf index 775bec5d..faa466fb 100644 --- a/urlhaus-filter-dnsmasq.conf +++ b/urlhaus-filter-dnsmasq.conf @@ -1,5 +1,5 @@ # Title: Malicious Domains dnsmasq Blocklist -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -238,7 +238,6 @@ address=/123mobile.store/0.0.0.0 address=/123moviesfx.com/0.0.0.0 address=/123sellfast.com/0.0.0.0 address=/123sex.co/0.0.0.0 -address=/123tadi.com/0.0.0.0 address=/123xyz.xyz/0.0.0.0 address=/124.com.ua/0.0.0.0 address=/124.cpanel.realwebsitesite.com/0.0.0.0 @@ -7094,7 +7093,6 @@ address=/app.bigplan-alex.com/0.0.0.0 address=/app.boxrcdn.com/0.0.0.0 address=/app.bridgeimpex.org/0.0.0.0 address=/app.calag.at/0.0.0.0 -address=/app.casetabs.com/0.0.0.0 address=/app.catholicchurch.co.in/0.0.0.0 address=/app.choiphui.com/0.0.0.0 address=/app.cloudindustry.net/0.0.0.0 @@ -11326,6 +11324,7 @@ address=/beanmatrix.com/0.0.0.0 address=/beansmedia.com/0.0.0.0 address=/beanssur.com/0.0.0.0 address=/beantreefoods.com/0.0.0.0 +address=/beanx88.xyz/0.0.0.0 address=/beanz-network.com/0.0.0.0 address=/bearcatpumps.com.cn/0.0.0.0 address=/beard-companies.com/0.0.0.0 @@ -17627,7 +17626,6 @@ address=/cdncomfortgroup.website/0.0.0.0 address=/cdndownloadlp.club/0.0.0.0 address=/cdnmultimedia.com/0.0.0.0 address=/cdnpic.mgyun.com/0.0.0.0 -address=/cdnrep.reimageplus.com/0.0.0.0 address=/cdnxh.net/0.0.0.0 address=/cdoconsult.com.br/0.0.0.0 address=/cdolechon.com/0.0.0.0 @@ -18370,7 +18368,6 @@ address=/cheapesthost.com.ng/0.0.0.0 address=/cheapgadgets-gq.000webhostapp.com/0.0.0.0 address=/cheapistan.pk/0.0.0.0 address=/cheapmlbjerseysmarlins.com/0.0.0.0 -address=/cheapmusic.info/0.0.0.0 address=/cheapoakleysunglasses.net/0.0.0.0 address=/cheappigeontraps.com/0.0.0.0 address=/cheapraccoontraps.com/0.0.0.0 @@ -18419,7 +18416,6 @@ address=/cheekie2.neagoeandrei.com/0.0.0.0 address=/cheematransxpressinc.com/0.0.0.0 address=/cheerchile.cl/0.0.0.0 address=/cheerfulgiversneverlack.com/0.0.0.0 -address=/cheerfullydo.com/0.0.0.0 address=/cheesecakery.com.br/0.0.0.0 address=/cheetahridge.mediadevstaging.com/0.0.0.0 address=/chef-solutions.dreamscape.co.in/0.0.0.0 @@ -18858,6 +18854,7 @@ address=/christina.makeyourselfelaborate.com/0.0.0.0 address=/christinablunsum.com/0.0.0.0 address=/christinailoveyousomuchyoumyheart.duckdns.org/0.0.0.0 address=/christinalenway.com/0.0.0.0 +address=/christinekeller.ch/0.0.0.0 address=/christinelebeck.com/0.0.0.0 address=/christinmunsch.com/0.0.0.0 address=/christmasatredeemer.org/0.0.0.0 @@ -24428,6 +24425,7 @@ address=/demo.jjmayurved.com/0.0.0.0 address=/demo.jrkcompany.com/0.0.0.0 address=/demo.kalapifoods.com/0.0.0.0 address=/demo.kanapebudapest.hu/0.0.0.0 +address=/demo.kechuahangdidong.com/0.0.0.0 address=/demo.kzonetechnologies.com/0.0.0.0 address=/demo.lamppostmedia.in/0.0.0.0 address=/demo.lapizblanco.com/0.0.0.0 @@ -26492,7 +26490,6 @@ address=/dl-45538429.onedrives-en-live.com/0.0.0.0 address=/dl-675423.store-downloads.com/0.0.0.0 address=/dl-80076342.md-downloads.com/0.0.0.0 address=/dl-97674424.md-downloads.com/0.0.0.0 -address=/dl-gameplayer.dmm.com/0.0.0.0 address=/dl-link.link/0.0.0.0 address=/dl-link.live/0.0.0.0 address=/dl-link.network/0.0.0.0 @@ -26523,7 +26520,6 @@ address=/dl.repairlabshost.com/0.0.0.0 address=/dl.rina-roleplay.com/0.0.0.0 address=/dl.river-store.com/0.0.0.0 address=/dl.rp-soft.ir/0.0.0.0 -address=/dl.softservers.net/0.0.0.0 address=/dl.svcupdate.com/0.0.0.0 address=/dl.teeqee.com/0.0.0.0 address=/dl.x420.me/0.0.0.0 @@ -27326,8 +27322,10 @@ address=/down.pcclear.com/0.0.0.0 address=/down.post-gg.top/0.0.0.0 address=/down.postch-b.top/0.0.0.0 address=/down.postch-bsw.top/0.0.0.0 +address=/down.postch-de.top/0.0.0.0 address=/down.postch-dfa.top/0.0.0.0 address=/down.postch-dj.top/0.0.0.0 +address=/down.postch-dl.top/0.0.0.0 address=/down.postch-fa.top/0.0.0.0 address=/down.postch-fj.top/0.0.0.0 address=/down.postch-kf.top/0.0.0.0 @@ -29138,7 +29136,6 @@ address=/economiadeltempo.it/0.0.0.0 address=/economiadigital.biz/0.0.0.0 address=/economika.com.ve/0.0.0.0 address=/economizei.shop/0.0.0.0 -address=/economplast.com/0.0.0.0 address=/economywindowcleaner.com/0.0.0.0 address=/econoteen.fea.usp.br/0.0.0.0 address=/econotel.us/0.0.0.0 @@ -33847,7 +33844,6 @@ address=/files.danwin1210.me/0.0.0.0 address=/files.dropmybin.me/0.0.0.0 address=/files.enjin.com/0.0.0.0 address=/files.gathercdn.com/0.0.0.0 -address=/files.hrloo.com/0.0.0.0 address=/files.l-d.tech/0.0.0.0 address=/files.martellexpress.us/0.0.0.0 address=/files.mirai-2viv.vn/0.0.0.0 @@ -36060,6 +36056,7 @@ address=/fuzzymiles.com/0.0.0.0 address=/fv1-2.failiem.lv/0.0.0.0 address=/fv13.failiem.lv/0.0.0.0 address=/fv15.failiem.lv/0.0.0.0 +address=/fv2-2.failiem.lv/0.0.0.0 address=/fv2-7.failiem.lv/0.0.0.0 address=/fv3.failiem.lv/0.0.0.0 address=/fv6.failiem.lv/0.0.0.0 @@ -40303,7 +40300,6 @@ address=/hangtotma.com/0.0.0.0 address=/hangtrentroi.com/0.0.0.0 address=/hangulcafes.ga/0.0.0.0 address=/hanh.cz/0.0.0.0 -address=/hanhtrinhtamlinh.com/0.0.0.0 address=/hanhtrinhthanhnienkhoinghiep.vn/0.0.0.0 address=/haniamarket.com/0.0.0.0 address=/hanict.org.vn/0.0.0.0 @@ -40498,7 +40494,6 @@ address=/harrisburgprinting.com/0.0.0.0 address=/harriscustomcatering.com/0.0.0.0 address=/harrisheatpumps.nz/0.0.0.0 address=/harrisnewtech.ir/0.0.0.0 -address=/harrisoncarter.com/0.0.0.0 address=/harrisonlily.co.uk/0.0.0.0 address=/harryfang.com/0.0.0.0 address=/harryhiggins.com/0.0.0.0 @@ -43299,7 +43294,6 @@ address=/i-sharecloud.com/0.0.0.0 address=/i-supportcharity.com/0.0.0.0 address=/i-vnsweyu.pl/0.0.0.0 address=/i-voda.com/0.0.0.0 -address=/i.fiery.me/0.0.0.0 address=/i.fluffy.cc/0.0.0.0 address=/i.funtourspt.eu/0.0.0.0 address=/i.ooxx.ooo/0.0.0.0 @@ -49680,6 +49674,7 @@ address=/kebunrayabaturraden.id/0.0.0.0 address=/kec-cendana.enrekangkab.go.id/0.0.0.0 address=/kec-wlingi.blitarkab.go.id/0.0.0.0 address=/kecforging.com/0.0.0.0 +address=/kechuahangdidong.com/0.0.0.0 address=/keciorenkoltukyikama.net/0.0.0.0 address=/keckarangdadap.pekalongankab.go.id/0.0.0.0 address=/kecsfila.hu/0.0.0.0 @@ -67483,6 +67478,7 @@ address=/osrsport.com/0.0.0.0 address=/ossandonycia.cl/0.0.0.0 address=/osscaar.com/0.0.0.0 address=/osservatore.betacom.it/0.0.0.0 +address=/ossi4.51cto.com/0.0.0.0 address=/ossianlaw.com/0.0.0.0 address=/osslusturv.com/0.0.0.0 address=/ossoriobouliz.com/0.0.0.0 @@ -70815,6 +70811,7 @@ address=/politinsky.000webhostapp.com/0.0.0.0 address=/politrix.net/0.0.0.0 address=/poliyzsl.host/0.0.0.0 address=/poljimenez.com/0.0.0.0 +address=/polk.k12.ga.us/0.0.0.0 address=/polka32.ru/0.0.0.0 address=/polkapower.com/0.0.0.0 address=/polkolonieb4k.pl/0.0.0.0 @@ -71986,7 +71983,6 @@ address=/professionalshop.in/0.0.0.0 address=/professionalwaiterskollege.org/0.0.0.0 address=/professionelelit.com/0.0.0.0 address=/professorsgallery.com/0.0.0.0 -address=/profetestruec.net/0.0.0.0 address=/profexsystem.com/0.0.0.0 address=/proffessia.ru/0.0.0.0 address=/proffice.com.pl/0.0.0.0 @@ -72364,6 +72360,7 @@ address=/protech.binarybizz.com/0.0.0.0 address=/protech.mn/0.0.0.0 address=/protechcarpetcare.com/0.0.0.0 address=/protechgroup1.com/0.0.0.0 +address=/protect.mimecast-offshore.com/0.0.0.0 address=/protectiadatelor.biz/0.0.0.0 address=/protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org/0.0.0.0 address=/protection.pecol.eu/0.0.0.0 @@ -80470,7 +80467,6 @@ address=/shareallfilesthroughsecureexchangesystem.duckdns.org/0.0.0.0 address=/sharebook.tk/0.0.0.0 address=/sharechautari.com/0.0.0.0 address=/shared-cnd.com/0.0.0.0 -address=/shared.pdffiller.com/0.0.0.0 address=/shareddocuments.ml/0.0.0.0 address=/shareddynamics.com/0.0.0.0 address=/sharedeconomy.eu/0.0.0.0 @@ -86099,6 +86095,7 @@ address=/sup3rc10ud.ga/0.0.0.0 address=/supadom.fr/0.0.0.0 address=/supamidland-my.sharepoint.com/0.0.0.0 address=/supcargo.com/0.0.0.0 +address=/supdate.mediaweb.co.kr/0.0.0.0 address=/super-filtr.ru/0.0.0.0 address=/super-gamezer.com/0.0.0.0 address=/super-industries.co/0.0.0.0 @@ -90717,7 +90714,6 @@ address=/tlcmoto.com/0.0.0.0 address=/tldrbox.top/0.0.0.0 address=/tlextreme.com/0.0.0.0 address=/tlfthelifefactory.com.au/0.0.0.0 -address=/tlgur.com/0.0.0.0 address=/tlkcloudem.com/0.0.0.0 address=/tlktdsfj.sha58.me/0.0.0.0 address=/tlpclient.site/0.0.0.0 @@ -92353,6 +92349,7 @@ address=/tsport88.com/0.0.0.0 address=/tsr-mark.xyz/0.0.0.0 address=/tsredco.telangana.gov.in/0.0.0.0 address=/tsrj.monster/0.0.0.0 +address=/tsrv2.top/0.0.0.0 address=/tst.marineindust.com/0.0.0.0 address=/tstfrigo.com/0.0.0.0 address=/tsugite.youbi.me/0.0.0.0 @@ -93764,6 +93761,7 @@ address=/update-chase.justmoveup.com/0.0.0.0 address=/update-prog.com/0.0.0.0 address=/update-res.100public.com/0.0.0.0 address=/update.5v.pl/0.0.0.0 +address=/update.7h4uk.com/0.0.0.0 address=/update.att.tools/0.0.0.0 address=/update.bracncet.net/0.0.0.0 address=/update.bruss.org.ru/0.0.0.0 @@ -94003,6 +94001,7 @@ address=/url-update.com/0.0.0.0 address=/url-validation-clients.com/0.0.0.0 address=/url.246546.com/0.0.0.0 address=/url.57569.fr.snd52.ch/0.0.0.0 +address=/url2.mailanyone.net/0.0.0.0 address=/url3.mailanyone.net/0.0.0.0 address=/url5459.41southbar.com/0.0.0.0 address=/url675.textilmallorca.com/0.0.0.0 @@ -95401,7 +95400,6 @@ address=/viettrungkhaison.com/0.0.0.0 address=/viettrust-vn.net/0.0.0.0 address=/vietucgroup.org/0.0.0.0 address=/vietup.net/0.0.0.0 -address=/vietvictory.vn/0.0.0.0 address=/vievioparapija.eu/0.0.0.0 address=/view-indonesia.com/0.0.0.0 address=/view-your-website.com/0.0.0.0 @@ -95855,6 +95853,7 @@ address=/visual-sounds.com/0.0.0.0 address=/visualblends.com/0.0.0.0 address=/visualdata.ru/0.0.0.0 address=/visualdimensioniq.com/0.0.0.0 +address=/visualdive.com/0.0.0.0 address=/visualendodontics.net/0.0.0.0 address=/visualgag.co.uk/0.0.0.0 address=/visualhome.cl/0.0.0.0 @@ -96933,7 +96932,6 @@ address=/wc2018.top/0.0.0.0 address=/wc3prince.ru/0.0.0.0 address=/wcare.nl/0.0.0.0 address=/wcbgroup.co.uk/0.0.0.0 -address=/wcdownloadercdn.lavasoft.com/0.0.0.0 address=/wcdr.pbas.es/0.0.0.0 address=/wcf-old.sibcat.info/0.0.0.0 address=/wcfamlaw.com/0.0.0.0 @@ -98599,6 +98597,7 @@ address=/workingin-my.sharepoint.com/0.0.0.0 address=/workingonit.site/0.0.0.0 address=/workingpainters.com/0.0.0.0 address=/workingroofers.com/0.0.0.0 +address=/workingsolutionsrome.org/0.0.0.0 address=/workingwell.club/0.0.0.0 address=/worklinic.com.br/0.0.0.0 address=/workmate-sien.com/0.0.0.0 @@ -100965,7 +100964,6 @@ address=/yoyoplease.com/0.0.0.0 address=/yoyoso.nz/0.0.0.0 address=/yoyoteacher.cn/0.0.0.0 address=/yp.dcyazilim.com/0.0.0.0 -address=/yp.hnggzyjy.cn/0.0.0.0 address=/ypbb.or.id/0.0.0.0 address=/ypddf.org/0.0.0.0 address=/ypicsdy.cf/0.0.0.0 @@ -101914,6 +101912,7 @@ address=/zoovetdv.ru/0.0.0.0 address=/zoox.com.br/0.0.0.0 address=/zoparo.nl/0.0.0.0 address=/zopbxtjiuykhyyp.usa.cc/0.0.0.0 +address=/zopro.duckdns.org/0.0.0.0 address=/zoracle.com/0.0.0.0 address=/zorancreative.com/0.0.0.0 address=/zoratech.ro/0.0.0.0 diff --git a/urlhaus-filter-domains-online.txt b/urlhaus-filter-domains-online.txt index 41411520..919b4369 100644 --- a/urlhaus-filter-domains-online.txt +++ b/urlhaus-filter-domains-online.txt @@ -1,5 +1,5 @@ # Title: Online Malicious Domains Blocklist -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -7,6 +7,7 @@ 0-24bpautomentes.hu 0cl.sldov.ru 1.11.234.99 +1.186.151.219 1.222.196.60 1.245.4.163 1.246.222.107 @@ -16,11 +17,9 @@ 1.246.222.134 1.246.222.138 1.246.222.14 -1.246.222.16 1.246.222.165 1.246.222.20 1.246.222.228 -1.246.222.232 1.246.222.234 1.246.222.237 1.246.222.245 @@ -41,6 +40,7 @@ 1.246.223.103 1.246.223.105 1.246.223.109 +1.246.223.126 1.246.223.127 1.246.223.130 1.246.223.146 @@ -78,12 +78,10 @@ 101.73.131.78 101.75.157.99 101.75.167.213 -101.99.94.15 102.130.115.14 102.141.240.139 103.113.99.79 103.125.218.107 -103.136.82.50 103.141.138.118 103.141.138.12 103.146.174.208 @@ -92,12 +90,11 @@ 103.217.215.21 103.224.200.146 103.224.200.40 -103.227.118.129 +103.237.21.36 103.238.228.4 103.240.249.121 103.4.117.26 103.70.160.51 -103.79.112.254 103.82.98.170 103.84.240.130 103.91.245.12 @@ -142,6 +139,7 @@ 109.124.90.229 109.233.196.232 109.235.7.228 +109.248.58.238 109.86.85.253 109.95.200.102 109.95.200.230 @@ -155,28 +153,27 @@ 110.228.195.46 110.241.119.168 110.248.124.254 +110.248.175.141 110.248.251.194 110.251.10.18 110.253.150.248 110.253.213.198 +110.253.51.112 110.255.101.184 110.255.167.147 110.35.145.127 110.35.208.21 -110.35.221.77 110.35.223.92 110.35.225.24 -110.35.233.147 110.35.235.57 +110.35.249.21 110.35.4.2 110fss.net -111.118.111.207 111.118.41.173 111.118.88.61 111.119.245.114 111.125.67.125 111.165.21.195 -111.165.248.134 111.166.236.191 111.167.151.156 111.170.85.71 @@ -193,22 +190,20 @@ 111.38.103.66 111.38.104.141 111.38.104.15 -111.38.106.128 111.38.106.19 111.38.121.222 111.38.121.223 111.38.121.226 111.38.121.228 111.38.26.243 +111.38.8.81 111.61.52.53 112.111.108.184 -112.111.31.175 112.133.222.151 112.147.92.51 112.159.108.96 112.163.200.217 112.170.124.75 -112.170.233.9 112.186.210.211 112.186.96.252 112.187.91.117 @@ -262,18 +257,15 @@ 112.247.81.173 112.247.82.122 112.248.148.90 -112.248.179.239 112.248.197.164 112.249.109.217 112.249.118.157 112.249.26.129 112.249.79.98 112.250.102.173 -112.250.57.99 112.251.218.210 112.252.136.84 112.252.196.17 -112.252.212.122 112.252.221.244 112.252.239.103 112.254.208.123 @@ -309,7 +301,6 @@ 112.27.124.177 112.27.124.178 112.27.124.179 -112.27.124.71 112.27.127.155 112.27.83.182 112.27.83.23 @@ -334,7 +325,6 @@ 112.30.1.91 112.30.110.31 112.30.110.36 -112.30.110.37 112.30.110.38 112.30.110.41 112.30.110.43 @@ -349,21 +339,23 @@ 112.30.4.136 112.30.4.52 112.31.240.239 -112.31.82.160 112.31.87.98 112.53.224.79 112.65.53.175 +112.72.153.37 +112.72.162.159 112.72.162.49 112.72.162.53 112.72.176.112 112.72.176.84 -112.72.231.35 +112.72.226.202 112.78.45.158 112.80.117.32 112.80.118.16 112.80.127.91 112.80.207.144 112.80.215.101 +112.80.218.56 112.82.146.253 112.82.18.255 112.82.224.139 @@ -381,16 +373,14 @@ 113.231.211.131 113.254.169.251 113.59.128.133 -113.59.136.39 +113.59.133.16 113.59.154.21 113.59.191.47 113.61.204.205 -113.87.174.63 -113.87.175.135 -113.89.42.50 113.89.43.185 113.90.26.136 -114.199.204.37 +114.111.242.3 +114.199.253.235 114.200.154.181 114.224.203.128 114.226.100.56 @@ -398,31 +388,24 @@ 114.229.165.194 114.235.115.236 114.30.54.64 -114.32.237.100 114.79.172.42 115.165.216.112 115.201.38.185 115.42.47.36 -115.48.204.56 115.50.21.56 115.51.125.55 115.52.18.65 -115.55.144.42 -115.55.145.147 115.55.153.194 -115.55.190.144 115.55.60.129 115.56.131.242 115.56.133.96 115.56.144.213 115.56.159.132 -115.56.187.173 115.58.132.140 115.58.165.147 -115.59.240.217 115.59.255.194 115.61.118.201 -115.62.26.39 +115.69.102.84 115.73.3.11 115.92.174.231 116.124.219.2 @@ -431,15 +414,21 @@ 116.211.100.26 116.212.132.119 116.212.142.215 -117.196.49.249 +117.194.166.219 117.196.50.107 117.20.204.138 117.20.204.5 117.20.210.52 +117.20.220.126 117.20.236.14 117.20.243.40 +117.20.247.150 117.200.76.54 -117.26.110.103 +117.202.66.15 +117.202.69.113 +117.213.10.108 +117.213.15.72 +117.248.63.12 117.63.113.146 117.63.195.140 117.63.53.15 @@ -464,12 +453,11 @@ 118.42.125.246 118.43.180.33 118.79.125.92 -118.79.218.157 118.79.50.203 118.79.58.82 -118.79.96.11 118.83.79.43 118.91.24.27 +118.91.41.135 118.99.179.164 118.99.183.235 118.99.239.217 @@ -480,7 +468,6 @@ 119.147.213.57 119.163.93.191 119.164.18.235 -119.164.218.229 119.165.107.93 119.165.163.220 119.165.174.63 @@ -493,8 +480,6 @@ 119.167.26.33 119.177.147.38 119.178.248.123 -119.179.157.219 -119.179.16.149 119.179.170.212 119.179.43.1 119.179.75.8 @@ -503,7 +488,6 @@ 119.180.108.227 119.180.108.79 119.180.33.161 -119.180.94.80 119.181.119.21 119.181.124.203 119.182.97.232 @@ -523,12 +507,12 @@ 119.251.105.221 119.251.14.251 119.56.131.155 +119.56.140.73 119.56.143.46 119.56.143.71 119.56.144.75 119.56.148.115 119.56.155.57 -119.56.172.28 119.56.175.41 119.56.195.90 119.56.206.43 @@ -559,22 +543,17 @@ 120.193.91.212 120.193.91.215 120.193.91.233 -120.209.121.243 120.209.126.206 120.209.126.240 120.209.127.187 120.209.99.127 120.210.89.79 120.43.33.202 -120.5.15.95 120.50.66.60 120.50.93.115 -120.6.141.142 120.6.8.11 120.7.75.99 120.85.173.168 -120.85.174.3 -120.85.210.232 121.100.114.164 121.100.96.8 121.121.44.222 @@ -595,10 +574,8 @@ 121.237.226.202 121.239.15.74 121.24.116.173 -121.25.101.86 121.254.43.215 121.254.76.17 -121.61.101.125 121.61.98.151 121.88.99.236 122.100.150.204 @@ -609,7 +586,6 @@ 122.199.66.28 122.199.72.23 122.199.79.27 -122.199.83.86 122.202.37.85 122.202.41.23 122.254.29.37 @@ -626,28 +602,26 @@ 123.128.133.91 123.129.84.36 123.130.208.52 -123.130.23.110 123.130.27.19 123.130.37.182 -123.130.61.210 -123.130.77.225 123.131.186.250 123.132.219.147 123.133.125.77 123.133.98.135 123.134.14.130 123.134.50.186 -123.14.120.130 123.14.199.130 +123.14.248.210 123.153.80.178 123.154.116.116 123.154.236.114 123.154.94.1 123.156.136.21 +123.159.68.119 123.159.8.100 123.183.121.60 -123.191.150.147 123.191.164.92 +123.191.62.239 123.192.101.163 123.192.194.233 123.193.149.235 @@ -672,13 +646,10 @@ 123.241.148.58 123.241.184.124 123.28.217.23 -123.5.189.116 123.5.5.242 -123.8.184.82 124.119.108.87 124.129.221.150 124.129.76.230 -124.130.110.167 124.130.40.31 124.131.104.82 124.131.151.135 @@ -691,7 +662,6 @@ 124.153.136.175 124.153.236.6 124.160.126.238 -124.163.163.193 124.163.65.64 124.163.72.102 124.165.123.7 @@ -715,8 +685,6 @@ 125.40.75.22 125.41.215.9 125.43.53.9 -125.45.63.67 -125.46.129.159 125.79.200.104 128.116.133.92 130.255.159.133 @@ -728,10 +696,12 @@ 139.216.102.151 139.227.46.137 14.102.17.222 +14.102.97.204 14.136.80.242 14.138.8.51 -14.178.163.235 +14.160.34.50 14.189.247.118 +14.241.227.216 14.37.222.190 14.45.127.110 14.46.25.17 @@ -758,23 +728,19 @@ 153.101.47.145 153.3.152.106 153.34.135.92 -153.36.126.35 155.138.134.44 158.101.165.14 158.174.213.128 -158.247.195.165 158.51.125.115 159.224.74.112 162.194.28.60 162.209.98.174 163.53.206.228 165.90.16.5 -168.205.223.254 170.81.238.178 171.113.36.216 171.113.38.107 171.121.255.10 -171.34.112.42 171.34.114.181 171.34.176.217 171.34.179.178 @@ -784,6 +750,7 @@ 172.114.244.127 172.245.5.185 172.245.5.190 +172.245.79.106 172.245.81.19 172.93.194.114 173.167.85.89 @@ -810,7 +777,6 @@ 175.169.13.182 175.201.104.192 175.208.230.8 -175.212.6.169 175.42.46.118 175.9.24.110 175.9.90.89 @@ -822,7 +788,6 @@ 176.111.174.67 176.113.161.104 176.113.161.113 -176.113.161.138 176.113.161.60 176.113.161.65 176.113.161.66 @@ -836,7 +801,7 @@ 176.123.7.127 176.123.9.243 176.124.7.225 -176.221.242.166 +176.221.188.251 176.240.84.106 177.11.92.78 177.131.226.235 @@ -846,35 +811,31 @@ 178.124.182.187 178.141.142.15 178.150.174.65 +178.151.143.2 178.165.122.141 178.175.0.200 178.175.1.137 -178.175.1.153 178.175.1.179 178.175.1.248 178.175.1.249 178.175.1.250 178.175.1.44 178.175.1.80 +178.175.100.151 +178.175.100.7 178.175.101.110 178.175.101.232 -178.175.102.133 178.175.102.171 178.175.102.67 178.175.103.98 -178.175.104.145 178.175.104.155 178.175.104.69 -178.175.105.125 178.175.105.95 -178.175.106.118 178.175.106.193 -178.175.106.201 178.175.107.0 178.175.107.245 178.175.107.83 178.175.108.105 -178.175.108.149 178.175.108.87 178.175.109.129 178.175.109.26 @@ -886,23 +847,19 @@ 178.175.111.206 178.175.112.135 178.175.112.139 +178.175.112.140 178.175.112.147 178.175.112.159 178.175.112.46 178.175.112.58 -178.175.113.27 178.175.114.114 -178.175.114.63 178.175.115.110 178.175.115.209 178.175.116.101 178.175.116.138 -178.175.116.168 -178.175.116.90 178.175.117.30 178.175.118.112 178.175.118.146 -178.175.118.210 178.175.119.102 178.175.119.114 178.175.119.69 @@ -923,18 +880,15 @@ 178.175.123.248 178.175.123.26 178.175.123.30 -178.175.123.48 178.175.123.91 178.175.124.131 178.175.124.155 178.175.124.4 -178.175.124.79 178.175.125.14 178.175.125.160 178.175.125.220 178.175.125.88 178.175.126.129 -178.175.126.153 178.175.126.252 178.175.126.46 178.175.127.202 @@ -944,7 +898,6 @@ 178.175.13.254 178.175.15.199 178.175.15.215 -178.175.15.35 178.175.16.108 178.175.16.116 178.175.16.251 @@ -953,20 +906,17 @@ 178.175.17.118 178.175.17.61 178.175.18.23 +178.175.18.37 178.175.18.75 178.175.19.163 178.175.19.174 178.175.19.91 -178.175.2.118 -178.175.2.123 178.175.2.209 178.175.2.5 178.175.20.117 178.175.20.70 178.175.20.97 178.175.21.149 -178.175.21.184 -178.175.21.238 178.175.22.237 178.175.23.144 178.175.23.176 @@ -978,7 +928,6 @@ 178.175.25.56 178.175.26.215 178.175.27.114 -178.175.27.127 178.175.27.171 178.175.27.213 178.175.27.32 @@ -986,18 +935,17 @@ 178.175.27.46 178.175.28.239 178.175.28.47 -178.175.29.2 178.175.29.21 178.175.3.172 178.175.3.214 178.175.30.133 178.175.30.151 178.175.30.213 -178.175.31.251 178.175.31.73 178.175.32.146 178.175.32.220 178.175.32.89 +178.175.33.162 178.175.33.7 178.175.34.217 178.175.34.247 @@ -1014,11 +962,12 @@ 178.175.4.144 178.175.4.72 178.175.40.136 -178.175.40.166 178.175.40.228 178.175.42.101 178.175.42.6 178.175.43.121 +178.175.43.223 +178.175.43.229 178.175.43.238 178.175.43.244 178.175.44.0 @@ -1031,13 +980,11 @@ 178.175.45.26 178.175.46.129 178.175.46.137 -178.175.46.243 178.175.46.41 178.175.46.42 178.175.46.8 178.175.47.143 178.175.48.51 -178.175.49.12 178.175.5.57 178.175.50.10 178.175.50.177 @@ -1056,10 +1003,8 @@ 178.175.56.82 178.175.56.87 178.175.57.134 -178.175.57.179 178.175.58.183 178.175.58.79 -178.175.59.131 178.175.59.33 178.175.6.115 178.175.6.140 @@ -1071,15 +1016,12 @@ 178.175.60.209 178.175.60.212 178.175.60.221 -178.175.61.235 -178.175.62.232 178.175.62.70 178.175.62.81 178.175.63.21 178.175.64.156 178.175.66.186 178.175.66.192 -178.175.66.211 178.175.68.116 178.175.68.123 178.175.68.209 @@ -1088,60 +1030,51 @@ 178.175.69.153 178.175.69.67 178.175.7.105 -178.175.7.107 178.175.7.14 -178.175.7.21 178.175.7.35 178.175.7.60 178.175.7.79 -178.175.70.212 178.175.70.218 +178.175.71.179 178.175.72.222 178.175.72.65 -178.175.73.42 178.175.75.181 178.175.75.244 -178.175.77.248 -178.175.77.46 178.175.77.47 178.175.78.169 178.175.78.2 -178.175.8.181 +178.175.78.242 178.175.80.89 -178.175.81.176 178.175.81.226 -178.175.81.235 178.175.81.31 178.175.83.2 +178.175.83.247 178.175.84.215 -178.175.84.61 178.175.85.23 178.175.85.53 178.175.86.59 178.175.87.146 178.175.87.42 178.175.87.91 -178.175.88.166 178.175.88.4 +178.175.89.121 178.175.89.217 178.175.89.6 178.175.9.179 178.175.9.198 178.175.9.4 -178.175.90.81 +178.175.90.4 178.175.92.1 178.175.92.102 178.175.92.92 178.175.93.143 -178.175.94.182 178.175.94.27 178.175.94.32 178.175.94.40 178.175.94.61 178.175.95.120 -178.175.96.218 178.175.96.251 -178.175.97.14 +178.175.97.113 178.175.98.83 178.175.99.120 178.175.99.130 @@ -1154,7 +1087,6 @@ 178.222.252.130 178.34.183.30 178.48.235.59 -178.72.91.172 178.95.136.35 179.159.58.134 179.60.84.7 @@ -1163,7 +1095,6 @@ 180.116.203.220 180.122.13.227 180.123.208.250 -180.125.44.194 180.157.66.204 180.175.236.209 180.176.105.41 @@ -1199,30 +1130,20 @@ 182.116.61.252 182.116.99.150 182.117.43.185 -182.117.43.82 182.119.120.8 182.119.164.128 -182.119.200.62 182.119.202.130 182.120.16.22 182.120.16.46 -182.121.127.106 -182.123.205.157 -182.123.211.239 -182.124.138.54 -182.126.121.211 +182.121.26.37 182.127.152.3 182.160.98.250 182.233.0.252 182.235.252.31 182.53.197.62 -183.105.104.83 183.105.225.154 183.109.169.45 183.128.152.115 -183.144.9.97 -183.185.112.19 -183.83.18.203 183.83.29.191 183.92.207.147 184.164.185.41 @@ -1249,7 +1170,6 @@ 185.68.230.207 185.81.157.186 185.82.217.185 -185.82.217.213 185.82.219.160 185.82.219.161 185.82.219.219 @@ -1268,7 +1188,6 @@ 187.12.10.98 187.188.124.229 187.212.200.162 -187.85.244.145 188.10.21.14 188.10.231.246 188.113.81.17 @@ -1277,6 +1196,8 @@ 188.143.220.152 188.152.41.141 188.169.178.50 +188.169.179.127 +188.169.199.59 188.242.242.144 188.81.100.83 188.83.202.25 @@ -1316,7 +1237,6 @@ 192.227.185.106 192.227.209.27 192.227.220.55 -192.227.223.96 192.227.228.67 192.227.230.74 192.3.152.166 @@ -1350,7 +1270,6 @@ 1am.co.nz 2.229.89.119 2.239.22.188 -2.249.161.188 2.37.149.230 2.37.203.65 2.45.4.24 @@ -1359,7 +1278,6 @@ 2.57.122.107 2.83.152.16 20.185.42.197 -200.104.150.167 200.105.167.98 200.111.189.70 200.194.4.24 @@ -1370,11 +1288,10 @@ 201.184.163.170 201.187.102.73 201.200.254.86 +201.203.221.20 201.203.27.37 -201.205.12.170 202.107.233.41 202.150.176.100 -202.166.217.54 202.175.103.10 202.29.95.12 202.4.124.58 @@ -1387,7 +1304,6 @@ 203.229.21.56 203.236.190.28 203.238.86.202 -203.243.142.132 203.70.166.107 203.77.80.159 203.80.119.166 @@ -1397,7 +1313,6 @@ 204.195.116.171 205.185.115.74 205.185.116.94 -205.185.123.217 206.248.137.132 206.47.41.166 207.180.228.101 @@ -1407,8 +1322,8 @@ 209.141.39.50 209.141.40.190 209.141.40.31 -209.141.46.87 210.124.149.19 +210.180.17.140 210.216.152.122 210.216.153.142 210.57.234.93 @@ -1419,7 +1334,6 @@ 211.116.220.37 211.187.132.204 211.187.75.220 -211.200.160.239 211.204.215.157 211.210.66.179 211.210.93.93 @@ -1437,31 +1351,31 @@ 212.46.197.114 212.56.197.230 212.8.251.211 +212.8.251.227 213.123.206.197 213.135.178.253 213.14.173.117 213.149.182.113 213.149.190.193 -213.163.104.12 213.163.104.99 213.163.113.135 213.163.113.20 213.163.113.237 213.163.113.6 213.163.114.165 +213.163.114.191 213.163.115.105 213.163.115.11 213.163.115.15 213.163.115.30 213.163.115.71 -213.163.116.192 213.163.117.151 +213.163.118.10 213.163.118.238 213.163.118.65 213.163.119.236 -213.163.126.175 +213.163.126.145 213.163.126.7 -213.163.127.107 213.163.127.46 213.189.178.163 213.240.218.15 @@ -1476,32 +1390,26 @@ 216.183.54.169 216.36.12.98 217.11.75.162 +217.127.133.214 218.12.181.110 218.2.40.34 218.234.165.18 218.238.246.3 -218.28.160.174 218.35.207.119 218.35.227.133 218.35.68.35 218.35.81.81 218.56.93.129 -218.58.92.253 218.59.116.203 -218.72.207.116 218.79.103.159 218.93.102.63 218.93.102.75 219.155.102.14 -219.155.11.207 -219.155.12.85 -219.155.26.190 219.155.29.165 219.156.186.18 219.157.139.165 219.157.150.91 219.157.214.235 -219.157.50.106 219.241.6.180 219.68.1.148 219.68.1.84 @@ -1510,19 +1418,17 @@ 219.68.245.63 219.68.5.140 219.69.71.186 +219.70.238.66 219.80.217.209 219.85.145.194 21robo.com 220.118.168.155 220.126.237.74 220.200.22.163 -220.247.91.17 220.71.239.115 -220.90.159.188 221.1.144.183 221.124.78.15 -221.15.113.234 -221.157.191.178 +221.15.125.69 221.160.136.213 221.202.232.230 221.214.130.147 @@ -1544,16 +1450,15 @@ 222.119.65.145 222.132.125.138 222.133.103.120 -222.135.67.115 222.135.9.5 222.137.148.192 222.137.211.78 222.138.17.132 222.138.237.155 222.140.17.245 -222.162.187.43 222.179.215.189 222.185.116.233 +222.186.20.19 222.187.9.178 222.211.72.66 222.236.85.220 @@ -1604,6 +1509,7 @@ 27.105.106.201 27.105.152.107 27.116.84.57 +27.14.211.219 27.14.81.201 27.141.218.17 27.147.29.52 @@ -1647,8 +1553,6 @@ 27.207.155.31 27.207.170.203 27.208.119.27 -27.208.152.10 -27.208.160.177 27.208.164.18 27.208.237.105 27.208.247.130 @@ -1658,13 +1562,13 @@ 27.209.208.122 27.209.231.15 27.210.107.125 -27.210.172.245 27.210.234.28 27.210.236.134 +27.210.32.122 27.210.44.19 27.210.63.243 27.213.104.201 -27.213.109.58 +27.213.109.105 27.213.175.208 27.213.255.202 27.213.66.112 @@ -1674,9 +1578,9 @@ 27.215.190.172 27.215.212.209 27.215.253.149 -27.215.34.242 27.215.71.243 27.215.98.242 +27.216.117.54 27.216.128.156 27.216.131.66 27.216.144.66 @@ -1698,17 +1602,13 @@ 27.220.85.168 27.221.239.223 27.222.241.223 -27.222.249.210 27.222.76.80 27.223.242.164 27.24.28.134 27.35.129.198 27.35.154.13 -27.35.16.145 -27.35.2.30 27.35.212.124 27.35.58.5 -27.41.237.129 27.43.117.98 31.0.98.131 31.11.51.57 @@ -1735,18 +1635,19 @@ 32.208.157.193 32792.prolocksmithwinterpark.com 35.184.169.169 -36.107.209.10 36.108.231.218 36.248.228.64 +36.248.83.98 36.250.203.246 36.251.157.225 36.251.18.18 36.251.51.244 36.255.90.219 +36.33.128.58 36.33.160.167 36.34.150.236 36.66.105.159 -36.66.111.203 +36.66.133.125 36.66.139.36 36.89.18.133 360.lcy2zzx.pw @@ -1816,7 +1717,6 @@ 39.81.70.88 39.83.94.11 39.84.115.152 -39.85.54.191 39.85.54.4 39.86.129.233 39.86.170.209 @@ -1827,10 +1727,10 @@ 39.88.155.96 39.88.233.131 39.88.67.238 +39.88.72.9 39.89.108.109 39.89.145.11 39.89.146.198 -39.89.146.36 39.89.63.23 39.90.86.212 40.88.2.151 @@ -1841,14 +1741,15 @@ 41.219.185.171 41.226.60.115 41.72.203.82 -41.86.18.169 -41.86.21.23 +41.86.18.133 41.86.21.27 -41.86.21.38 +41.86.5.197 42.202.101.199 +42.228.39.211 42.228.43.161 42.228.65.104 42.230.82.176 +42.232.81.179 42.235.180.147 42.239.26.122 42.56.15.227 @@ -1862,7 +1763,9 @@ 45.133.1.242 45.133.203.192 45.135.134.228 +45.14.149.182 45.14.149.204 +45.141.84.182 45.141.84.184 45.144.225.118 45.144.225.135 @@ -1888,16 +1791,12 @@ 45.51.104.59 45.6.24.251 45.81.235.31 -45.85.90.131 -45.85.90.179 45.85.90.203 45.9.148.37 45.92.108.125 -45.95.169.153 46.117.42.29 46.172.75.231 46.182.173.246 -46.182.173.247 46.20.63.218 46.214.27.4 46.24.130.254 @@ -1915,6 +1814,7 @@ 47.16.131.51 47.21.202.98 47.46.231.38 +49.119.187.230 49.142.162.113 49.142.87.36 49.143.43.93 @@ -1929,7 +1829,6 @@ 49.68.221.252 5.188.62.111 5.2.70.50 -5.42.37.74 5.53.146.179 5.79.75.210 5.95.226.154 @@ -1937,7 +1836,6 @@ 50.115.174.106 50.121.91.255 50.252.47.29 -51.222.56.159 54.36.114.136 54.36.180.122 58.114.246.26 @@ -1952,16 +1850,15 @@ 58.218.67.253 58.22.212.107 58.226.129.29 -58.229.194.122 58.230.89.42 58.238.42.192 58.240.147.97 58.241.78.55 -58.243.123.212 58.243.126.133 58.243.208.225 -58.248.118.64 -58.249.80.181 +58.248.142.227 +58.249.79.174 +58.249.84.131 58.48.154.143 58.72.165.153 58.72.165.39 @@ -1970,12 +1867,14 @@ 59.0.211.161 59.102.168.189 59.151.202.3 -59.151.207.150 59.151.214.4 59.151.237.51 59.151.246.125 59.23.114.97 59.58.117.226 +59.93.18.144 +59.96.37.124 +59.97.169.237 60.10.91.242 60.13.61.12 60.164.130.220 @@ -2000,9 +1899,7 @@ 60.217.177.196 60.217.86.208 60.223.84.102 -60.25.109.240 60.253.15.104 -60.253.39.88 60.253.4.72 60.253.51.127 60.253.60.174 @@ -2012,25 +1909,21 @@ 60.7.8.43 60.7.99.254 61.164.96.98 -61.179.171.60 61.179.91.194 61.247.224.66 61.253.94.230 -61.3.149.112 61.41.230.161 61.47.220.169 61.52.103.217 61.52.199.47 -61.52.207.10 61.52.30.172 61.52.9.166 -61.52.9.62 61.52.99.161 -61.53.102.137 61.53.117.237 -61.53.220.0 +61.53.89.220 61.54.103.56 61.54.64.63 +61.54.69.77 61.56.180.67 61.56.181.7 61.57.96.116 @@ -2131,7 +2024,6 @@ 74.64.139.223 74.75.165.81 75.127.141.52 -75.82.36.220 75.83.102.27 75.99.213.61 76.170.11.82 @@ -2143,7 +2035,6 @@ 76.95.12.137 77.111.182.31 77.237.25.210 -77.53.144.46 77.71.50.153 77.71.52.220 77.89.203.238 @@ -2165,6 +2056,7 @@ 79.130.253.13 79.147.123.48 79.175.42.244 +79.21.84.63 79.7.170.58 79.79.58.94 79.8.70.162 @@ -2178,6 +2070,7 @@ 81.165.44.109 81.191.40.58 81.213.141.184 +81.215.199.29 81.218.187.113 81.218.195.216 81.237.128.200 @@ -2245,7 +2138,7 @@ 86.35.43.220 87.172.19.130 87.61.89.40 -87du.vip +88.119.171.253 88.2.208.71 88.2.219.179 88.225.222.128 @@ -2279,6 +2172,7 @@ 92.114.191.82 92.241.78.114 92.27.246.202 +92.54.237.237 92.83.62.139 92.85.18.138 93.159.169.190 @@ -2306,7 +2200,6 @@ 95.60.146.134 95.66.196.63 95.9.120.40 -95.9.81.85 96.239.73.246 96.47.147.169 97.68.140.254 @@ -2378,6 +2271,7 @@ anadelgbt.org anantam.net.in andreelapeyre.com andremaraisbeleggings.co.za +andreonemaia.com andres.ac.ug andres.ug andreshconcejal.solucioneslink.com @@ -2387,7 +2281,6 @@ angloteste.bigprime.com.br anhung1102.vn anurontv.com anysbergbiltong.co.za -apartamentoscitta.com api-ms.cobainaja.id api.cstdevs.com api.quocbao.biz @@ -2410,15 +2303,17 @@ atlasconcreteworks.com attach.66rpg.com atteuqpotentialunlimited.com augustair.com +aulist.com +automaticrefreshments.com avadhanagames.com ayahuascasp.com.br ayamallah.com +aycconsultoriaempresarial.com azmeasurement.com b2b.toptanakaryakit.com.tr backgrounds.pk badeggdesign.com balealgodon.mx -ballina.andrewmaughan.com bangkok-orchids.com bangladeshunbound.com bary.sz4h.com @@ -2429,6 +2324,7 @@ bbia.co.uk bcmt.elin.co.za bcrg.co.za bdnextrend.xyz +beanx88.xyz bearcatpumps.com.cn beautincollagen.rs bekape.co.id @@ -2436,6 +2332,7 @@ beor360.com bespokeweddings.ie bestcarenepal.com betone.co.kr +betycopaints.com beveragesmiami.solucioneslink.com bhavaniengineering.com bigmikesupplies.co.za @@ -2464,6 +2361,7 @@ bophelocare.co.za bounces.mi-fs.com boutiqueofferte.com bpo.correct.go.th +bradleyinstitute.co.za brandtrust.com.pk braunfinancial.com.au brendanquine.com @@ -2514,6 +2412,7 @@ chezalice.co.za childselect.com chinhdropfile.myvnc.com chinhdropfile80.myvnc.com +chipmania.it cible-energy.com cifeer.net cirugiadenarizbucaramanga.com @@ -2527,10 +2426,9 @@ cloud.fc.co.mz cm-arquitetos.com codsambal.com colempaques.info -colinde.pricesne.com colorpak.pl +columbia.aula-web.net community.reimclub.com -comosairdoburaco.com.br competancy.indigoconsult.net conceptimagine.ro config.cqhbkjzx.com @@ -2546,7 +2444,6 @@ covid19.cyberschool.or.id cpanel.shivay.net cr-sq.com craftech.nxtnet.ga -crearechile.cl creationskateboards.com crecerco.com crittersbythebay.com @@ -2556,7 +2453,6 @@ crmroche.manivelasst.com crscorretordeimoveis.com.br cse-engineer.com csnserver.com -ctracknxt.in cubescargoexpress.com curasoles.co.za currantmedia.com @@ -2575,7 +2471,6 @@ data.cdevelop.org data.over-blog-kiwi.com datapolish.com dating.khokhas.co.za -datsom.vn davethompson.me.uk davidmcguinness.info dayspringdaisies.com @@ -2599,7 +2494,6 @@ destinymc.co.za detorre.es dev.sebpo.net dev.watch-store.eu -dezcom.com dfcf.91756.cn dfsfcsfcdsfsdvcfsvcscv.com diamantenegro.mi-fs.com @@ -2614,6 +2508,7 @@ dl.installcdn-aws.com dl.packetstormsecurity.net dl.rina-roleplay.com dnn.alibuf.com +dns.alibuf.com dns.cyberium.cc dockerupdate.anondns.net docman.orientalservices.in @@ -2630,6 +2525,8 @@ dosame.com dosman.pl dovberger.com down.pcclear.com +down.postch-de.top +down.postch-dl.top down.udashi.com down.webbora.com down1.arpun.com @@ -2689,14 +2586,13 @@ extrovertoffers.com f1sol.com fahrzeugdrive.com familydentist.site -faveraprojects.com fc.co.mz felicienne.nl files.martellexpress.us filmotainment.com final.makkahkmcc.com fineartgallerym.com -fisconline.casa +fisconline.bar fix-america-now.org fixauto.illumetechnology.com fixturegovernment.com @@ -2711,7 +2607,6 @@ foothills.com.br footweardirect.elin.co.za forum.mdb.nu fotoobjetivo.com -foundationrepairhoustontx.net foxeps.com.br fraud.bpcbankingtech.com freecnetdownload.com @@ -2720,7 +2615,6 @@ ftp.n3twork30cm.ml fullelectronica.com.ar funletters.net fusionfiresolutions.com -futbolpr.com futuregraphics.com.ar g.pinmonkey.xyz gametwogame.com @@ -2737,6 +2631,7 @@ ghettohub.co.za ghislain.dartois.pagesperso-orange.fr giadungg7.com giddos.ga +giteletropical.com glowinmedia.co.ke gmsebpl.com gmtransformationacademy.com @@ -2749,6 +2644,7 @@ goldcoastoffice365.com goldcoastoffice365.com.au golden-memories-funerals.yourpageserver.com goldenasiacapital.com +goldmen.in gorecycle.fahadjutt.com gpotecnosystems.com gracejukes.com @@ -2777,13 +2673,12 @@ hhaward.org highlandroadcoc.com highlandslasvegas.atakdev.com hindi.factsriver.com -hiptool.net hitpe.com hitstation.nl +hlmd.in hmpmall.co.kr hoagietesting10.com hoayeuthuong-my.sharepoint.com -holmesservices.mobiledevsite.co homefindersolutions.com hongluosi.com hookedupboatclub.com @@ -2794,7 +2689,6 @@ houstonshutters.site hr2019.vrcom7.com hrnautica.com.br hseda.com -hsmwebapp.com htownbars.com hubtech.co.za huellacero.cl @@ -2834,16 +2728,19 @@ ioabc.wif.com.br ipmes.ma iremart.es iris101.co.uk +isaac.mikhailmotoringschool.com iscamenabe.com isiphephelocon.co.za iso-dubai.net israrulhaq.me +isrorg.com isso.ps ist-security.com it123.ru italiandirezione.casa itc-demo.softgig.co.ke itelsys.ma +itmotasaciones.com jacktech.jackindia.com jaishritours.com jamiekaylive.com @@ -2857,6 +2754,7 @@ jennwolfemtb.com jhayesconsulting.com jiaoyuzixun.cn jing-da.com.tw +jmtc.91756.cn jnanbharati.com jobs.thebeessolution.com joelbonissilver.com @@ -2867,6 +2765,7 @@ jumpmanualjacobhiller.com jupiter.toxsl.in justinscott.com.au kadigital.co.uk +kaizenjanitorial.com kalawatihomes.com kalogirosfinance.com kaptaanchapal.com @@ -2928,14 +2827,16 @@ lotusanddragonfly.com lp.definerisco.com lp.difusodesign.com lp.quama.pe -ltc.typoten.com +luckybrownie.com luminouspneuma.com luxomodels.com m-technics.kz m.estudiomoros.com.ar m.mobilelocalsales.com +m.softsharks.com madicon.co.za magianegramagiablancayamarres.com +maharaniworld.com mail.bs-eiendomme.co.za mail.golimoapp.com mail.jeffsono.org @@ -2961,7 +2862,6 @@ matruchhaya.co.in maxiquim.cl maxoprint.co.uk maxtox.com.pk -maybethescobar.com mbgrm.com mbjtimes.com mbsolutions.ge @@ -2992,11 +2892,12 @@ michaelphilip.com michimal2.000webhostapp.com microblading.mirliandias.com.br microcomm-group.com +mikhailmotoringschool.com +mills-skyla30ec.com mingguanwms.com minuevavida.org mirror.mypage.sk misterson.com -mixr.at mkontakt.az mktf.mx mmdx.com @@ -3033,6 +2934,7 @@ navayurveda.in nec-i.com nedkellymyanmar.com nelitrianggraeni.000webhostapp.com +nellaimasthanbiryani.com nerve.untergrund.net nettube.com.br networkwheels.co.za @@ -3057,7 +2959,6 @@ njtiledesigncenter.com nobius.org nocalnoodle.elin.co.za nomadicbees.com -nonnarina.ax notamuzikaletleri.com ns1.the-widyantos.com nsb.org.uk @@ -3077,12 +2978,15 @@ omaromatic.com omega.az oms.pappai.com omscoc.pappai.com +onedigitalcard.granvizionnecorp.com onedrive.listifyapp.co online.creedglobal.in onlinestatis.bar +open.rawntech.com open.warehousesaas.co.uk opentoronto.org opolis.io +opticaoptigral.cl optimus.com.sg order.bizpeed.com orientgatewayltd.com @@ -3120,6 +3024,7 @@ pcsoori.com pd.oceaniarp.net pemdodo.com perfumeriamontes.es +periodiche.bar perpus.onlineman7-jombang.sch.id perpustekim.untirta.ac.id pestoclean.co.uk @@ -3139,6 +3044,7 @@ pmglance.startwriteup.com pointactionsg.com pokojewewladyslawowie.pl pole.com.vc +ponchokhana.com pool.phxdir.com pooltablemoversdenver.net portal.premiumpunch.com @@ -3149,6 +3055,7 @@ prestasicash.com.ar prestigehomeautomation.net preview2.behalen.com prishaartcreations.com +prismaxis.com production.sparshims.com programaoperadoronline.com.br project.exquitec.com @@ -3200,7 +3107,6 @@ reseller.itechbrasil.com resuco.net rezkabum.ru rhema.com.sg -richancyber.info richmondminerals.co.zm rinaefoundation.org.za rinkaisystem-ht.com @@ -3209,7 +3115,6 @@ rkcable.co.in rkverify.securestudies.com robertmcardle.com robertsinclair.net -romanianpoints.com ronnietucker.co.uk roomsvc.servegate.kr roshnijewellery.com @@ -3219,7 +3124,6 @@ rubycityvietnam.com ruisgood.ru ruwadalkuwait.com rydchile.cl -s.51shijuan.com s.thechinesemuslim.com sac2.11xii.com sacredscentsonline.com @@ -3253,7 +3157,9 @@ serendibsourcing.com sericaasia.com servicemhkd.myvnc.com servicemhkd80.myvnc.com +serviciovirtual.com.ar sexologistpakistan.net +seyranikenger.com.tr sgb.ac.ke sgessy.com.br shaheentbfoundation.com @@ -3304,6 +3210,7 @@ spaceframe.mobi.space-frame.co.za special-key.cf spent.com.pl spetsesyachtcharter.gr +spiritualroot.org spititourism.com spittinfire.com sports-net.de @@ -3323,7 +3230,7 @@ stiepancasetia.ac.id stlukesohag.com store.ericalgarin.com stott-thompson.co.uk -streetdemo.yourpageserver.com +stratexec.co.za suboldesign.com sumerians.org sunaryem.com.tr @@ -3371,6 +3278,7 @@ test.lubrico.in test.typoten.com test.wanepghana.org test1.asistencia247.com +test1.milenial.id test1.tenplusone.my test2.basis-web.com test2.marrenconstruction.ie @@ -3395,7 +3303,7 @@ themansionkasauli.com theprofinn.com thesummitpc.net theurbantutors.com -thientu.net +thirdstringcalifornia.com thosewebbs.com thriveink.com tianangdep.com @@ -3405,7 +3313,6 @@ timamollo.co.za timegonebuy.com tksb.net tlcc.com.gt -tntmedia.gr todoapp.cstdevs.com todocontodo.com.mx tonydong.com @@ -3442,6 +3349,7 @@ ultimate-24.de umwelt-kirchhof.de unicorpbrunei.com uniengrisb.com +unisoftcc.com unyazitelecom.com upcbpta.com urbantrapfest.cl @@ -3456,7 +3364,9 @@ vbcargo.hu vcah.co.uk vectarts.com vegadelcasero.cl +velma-harber30ku.com vendas.lidiacarmeli.com.br +versualstudio.com veterinariadrpopui.com vfocus.net vienen.gblix.srv.br @@ -3483,6 +3393,7 @@ vvsskmodinationalschool.com w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu wanepliberia.org wanepniger.org +weareactum.com web.eng.ubu.ac.th web.geetle.ga web.geomegasoft.net @@ -3510,6 +3421,7 @@ wolfgang-brodte.de wonderhawaii.com woodsytech.com wordpress.saleensuporte.com.br +workingsolutionsrome.org wozata.000webhostapp.com wp.readhere.in wpdemo.101clients.com.au @@ -3531,7 +3443,6 @@ yoast.yourpageserver.com yourclub1.com yourtopdog.com.au youtubetrainingacademy.com -yp.hnggzyjy.cn yskadvisors.com yummyyogaudaipur.com yzkzixun.com diff --git a/urlhaus-filter-domains.txt b/urlhaus-filter-domains.txt index de9d0570..373f01e7 100644 --- a/urlhaus-filter-domains.txt +++ b/urlhaus-filter-domains.txt @@ -1,5 +1,5 @@ # Title: Malicious Domains Blocklist -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -2024,6 +2024,7 @@ 101.109.78.164 101.109.85.37 101.109.85.40 +101.126.102.31 101.126.155.223 101.126.87.66 101.128.72.166 @@ -3771,6 +3772,7 @@ 103.217.123.137 103.217.123.14 103.217.123.142 +103.217.123.143 103.217.123.145 103.217.123.147 103.217.123.151 @@ -4420,6 +4422,7 @@ 103.41.25.189 103.41.25.201 103.41.25.203 +103.41.25.206 103.41.25.21 103.41.25.212 103.41.25.233 @@ -12058,6 +12061,7 @@ 111.92.80.176 111.92.80.182 111.92.80.183 +111.92.80.192 111.92.80.195 111.92.80.196 111.92.80.20 @@ -20047,6 +20051,7 @@ 112.80.215.101 112.80.215.227 112.80.215.229 +112.80.218.56 112.80.236.136 112.80.236.158 112.80.236.45 @@ -50018,6 +50023,7 @@ 115.56.130.27 115.56.130.30 115.56.130.32 +115.56.130.33 115.56.130.5 115.56.130.52 115.56.130.55 @@ -93130,6 +93136,7 @@ 116.68.97.187 116.68.97.192 116.68.97.193 +116.68.97.199 116.68.97.2 116.68.97.204 116.68.97.212 @@ -116913,6 +116920,7 @@ 117.202.69.110 117.202.69.111 117.202.69.112 +117.202.69.113 117.202.69.114 117.202.69.115 117.202.69.116 @@ -118554,6 +118562,7 @@ 117.208.135.217 117.208.135.218 117.208.135.22 +117.208.135.220 117.208.135.225 117.208.135.227 117.208.135.229 @@ -119413,6 +119422,7 @@ 117.212.52.160 117.212.54.132 117.212.55.67 +117.213.10.108 117.213.10.115 117.213.10.125 117.213.10.140 @@ -119467,6 +119477,7 @@ 117.213.15.238 117.213.15.29 117.213.15.43 +117.213.15.72 117.213.40.10 117.213.40.100 117.213.40.102 @@ -120939,6 +120950,7 @@ 117.215.208.107 117.215.208.11 117.215.208.116 +117.215.208.14 117.215.208.143 117.215.208.149 117.215.208.153 @@ -123259,6 +123271,7 @@ 117.222.169.229 117.222.169.23 117.222.169.231 +117.222.169.232 117.222.169.234 117.222.169.236 117.222.169.239 @@ -129854,6 +129867,7 @@ 118.24.9.62 118.246.199.1 118.246.246.125 +118.246.38.170 118.249.136.112 118.249.136.98 118.249.137.218 @@ -151897,6 +151911,7 @@ 123.14.248.189 123.14.248.19 123.14.248.208 +123.14.248.210 123.14.248.212 123.14.248.216 123.14.248.221 @@ -153319,6 +153334,7 @@ 123.159.30.49 123.159.31.110 123.159.51.112 +123.159.68.119 123.159.68.151 123.159.68.26 123.159.68.31 @@ -153595,6 +153611,7 @@ 123.191.6.244 123.191.6.93 123.191.60.197 +123.191.62.239 123.191.63.187 123.191.7.209 123.191.79.120 @@ -162356,7 +162373,6 @@ 123moviesfx.com 123sellfast.com 123sex.co -123tadi.com 123xyz.xyz 124.100.74.153 124.105.105.222 @@ -202115,6 +202131,7 @@ 178.141.47.227 178.141.47.70 178.141.48.109 +178.141.48.178 178.141.48.43 178.141.48.82 178.141.49.101 @@ -202596,6 +202613,7 @@ 178.175.100.58 178.175.100.61 178.175.100.65 +178.175.100.7 178.175.100.70 178.175.100.75 178.175.100.77 @@ -202775,6 +202793,7 @@ 178.175.102.211 178.175.102.214 178.175.102.216 +178.175.102.219 178.175.102.22 178.175.102.220 178.175.102.221 @@ -203906,6 +203925,7 @@ 178.175.112.136 178.175.112.138 178.175.112.139 +178.175.112.140 178.175.112.147 178.175.112.148 178.175.112.15 @@ -206281,6 +206301,7 @@ 178.175.18.27 178.175.18.32 178.175.18.36 +178.175.18.37 178.175.18.38 178.175.18.42 178.175.18.45 @@ -209018,7 +209039,9 @@ 178.175.43.217 178.175.43.22 178.175.43.220 +178.175.43.223 178.175.43.227 +178.175.43.229 178.175.43.231 178.175.43.232 178.175.43.234 @@ -209105,6 +209128,7 @@ 178.175.44.158 178.175.44.162 178.175.44.165 +178.175.44.166 178.175.44.168 178.175.44.169 178.175.44.171 @@ -212135,6 +212159,7 @@ 178.175.71.174 178.175.71.175 178.175.71.178 +178.175.71.179 178.175.71.180 178.175.71.185 178.175.71.189 @@ -212858,6 +212883,7 @@ 178.175.78.234 178.175.78.236 178.175.78.240 +178.175.78.242 178.175.78.243 178.175.78.244 178.175.78.246 @@ -214976,6 +215002,7 @@ 178.175.97.110 178.175.97.111 178.175.97.112 +178.175.97.113 178.175.97.116 178.175.97.118 178.175.97.12 @@ -217501,6 +217528,7 @@ 180.188.241.194 180.188.241.2 180.188.241.201 +180.188.241.203 180.188.241.215 180.188.241.216 180.188.241.219 @@ -240019,6 +240047,7 @@ 182.121.26.242 182.121.26.251 182.121.26.35 +182.121.26.37 182.121.26.56 182.121.26.58 182.121.26.77 @@ -272292,6 +272321,7 @@ 202.164.138.185 202.164.138.187 202.164.138.188 +202.164.138.19 202.164.138.192 202.164.138.195 202.164.138.196 @@ -276891,6 +276921,7 @@ 209.14.30.183 209.14.30.204 209.14.30.205 +209.14.30.209 209.14.30.212 209.14.30.213 209.14.30.216 @@ -276917,6 +276948,7 @@ 209.14.31.190 209.14.31.192 209.14.31.201 +209.14.31.209 209.14.31.215 209.14.31.217 209.14.31.220 @@ -276929,6 +276961,7 @@ 209.14.31.243 209.14.31.244 209.14.31.247 +209.14.31.249 209.14.31.252 209.14.31.253 209.14.31.55 @@ -277497,6 +277530,7 @@ 210.18.189.89 210.18.189.9 210.18.189.90 +210.180.17.140 210.180.237.212 210.182.101.144 210.182.148.126 @@ -290467,6 +290501,7 @@ 220.133.1.130 220.133.103.166 220.133.109.249 +220.133.110.157 220.133.114.189 220.133.115.57 220.133.117.229 @@ -316242,6 +316277,7 @@ 27.210.29.26 27.210.29.83 27.210.3.50 +27.210.32.122 27.210.32.123 27.210.32.125 27.210.32.130 @@ -317685,6 +317721,7 @@ 27.216.116.240 27.216.116.81 27.216.117.178 +27.216.117.54 27.216.118.234 27.216.119.219 27.216.119.228 @@ -346923,6 +346960,7 @@ 36.248.227.203 36.248.228.64 36.248.82.234 +36.248.83.98 36.248.88.35 36.248.92.154 36.248.93.13 @@ -362404,6 +362442,7 @@ 42.226.83.71 42.226.83.78 42.226.83.98 +42.226.85.236 42.226.86.204 42.226.87.123 42.226.88.114 @@ -364695,6 +364734,7 @@ 42.228.39.197 42.228.39.2 42.228.39.204 +42.228.39.211 42.228.39.212 42.228.39.214 42.228.39.215 @@ -372446,6 +372486,7 @@ 42.232.81.147 42.232.81.149 42.232.81.176 +42.232.81.179 42.232.81.181 42.232.81.183 42.232.81.188 @@ -386683,6 +386724,7 @@ 49.117.191.46 49.117.191.78 49.117.191.83 +49.119.187.230 49.119.188.56 49.119.189.124 49.119.189.223 @@ -390365,6 +390407,7 @@ 58.248.142.212 58.248.142.214 58.248.142.223 +58.248.142.227 58.248.142.23 58.248.142.230 58.248.142.236 @@ -391604,6 +391647,7 @@ 58.249.79.16 58.249.79.163 58.249.79.17 +58.249.79.174 58.249.79.175 58.249.79.188 58.249.79.195 @@ -391800,6 +391844,7 @@ 58.249.84.118 58.249.84.124 58.249.84.128 +58.249.84.131 58.249.84.134 58.249.84.148 58.249.84.150 @@ -403297,6 +403342,7 @@ 59.96.37.121 59.96.37.122 59.96.37.123 +59.96.37.124 59.96.37.125 59.96.37.127 59.96.37.128 @@ -407719,6 +407765,7 @@ 59.99.43.187 59.99.43.19 59.99.43.190 +59.99.43.191 59.99.43.192 59.99.43.193 59.99.43.194 @@ -430554,6 +430601,7 @@ 61.53.89.199 61.53.89.2 61.53.89.208 +61.53.89.220 61.53.89.221 61.53.89.227 61.53.89.232 @@ -431632,6 +431680,7 @@ 61.54.69.62 61.54.69.69 61.54.69.70 +61.54.69.77 61.54.69.78 61.54.69.8 61.54.69.95 @@ -445984,7 +446033,6 @@ app.bigplan-alex.com app.boxrcdn.com app.bridgeimpex.org app.calag.at -app.casetabs.com app.catholicchurch.co.in app.choiphui.com app.cloudindustry.net @@ -450216,6 +450264,7 @@ beanmatrix.com beansmedia.com beanssur.com beantreefoods.com +beanx88.xyz beanz-network.com bearcatpumps.com.cn beard-companies.com @@ -456517,7 +456566,6 @@ cdncomfortgroup.website cdndownloadlp.club cdnmultimedia.com cdnpic.mgyun.com -cdnrep.reimageplus.com cdnxh.net cdoconsult.com.br cdolechon.com @@ -457260,7 +457308,6 @@ cheapesthost.com.ng cheapgadgets-gq.000webhostapp.com cheapistan.pk cheapmlbjerseysmarlins.com -cheapmusic.info cheapoakleysunglasses.net cheappigeontraps.com cheapraccoontraps.com @@ -457309,7 +457356,6 @@ cheekie2.neagoeandrei.com cheematransxpressinc.com cheerchile.cl cheerfulgiversneverlack.com -cheerfullydo.com cheesecakery.com.br cheetahridge.mediadevstaging.com chef-solutions.dreamscape.co.in @@ -457748,6 +457794,7 @@ christina.makeyourselfelaborate.com christinablunsum.com christinailoveyousomuchyoumyheart.duckdns.org christinalenway.com +christinekeller.ch christinelebeck.com christinmunsch.com christmasatredeemer.org @@ -463318,6 +463365,7 @@ demo.jjmayurved.com demo.jrkcompany.com demo.kalapifoods.com demo.kanapebudapest.hu +demo.kechuahangdidong.com demo.kzonetechnologies.com demo.lamppostmedia.in demo.lapizblanco.com @@ -465382,7 +465430,6 @@ dl-45538429.onedrives-en-live.com dl-675423.store-downloads.com dl-80076342.md-downloads.com dl-97674424.md-downloads.com -dl-gameplayer.dmm.com dl-link.link dl-link.live dl-link.network @@ -465413,7 +465460,6 @@ dl.repairlabshost.com dl.rina-roleplay.com dl.river-store.com dl.rp-soft.ir -dl.softservers.net dl.svcupdate.com dl.teeqee.com dl.x420.me @@ -466216,8 +466262,10 @@ down.pcclear.com down.post-gg.top down.postch-b.top down.postch-bsw.top +down.postch-de.top down.postch-dfa.top down.postch-dj.top +down.postch-dl.top down.postch-fa.top down.postch-fj.top down.postch-kf.top @@ -468028,7 +468076,6 @@ economiadeltempo.it economiadigital.biz economika.com.ve economizei.shop -economplast.com economywindowcleaner.com econoteen.fea.usp.br econotel.us @@ -472737,7 +472784,6 @@ files.danwin1210.me files.dropmybin.me files.enjin.com files.gathercdn.com -files.hrloo.com files.l-d.tech files.martellexpress.us files.mirai-2viv.vn @@ -474950,6 +474996,7 @@ fuzzymiles.com fv1-2.failiem.lv fv13.failiem.lv fv15.failiem.lv +fv2-2.failiem.lv fv2-7.failiem.lv fv3.failiem.lv fv6.failiem.lv @@ -479193,7 +479240,6 @@ hangtotma.com hangtrentroi.com hangulcafes.ga hanh.cz -hanhtrinhtamlinh.com hanhtrinhthanhnienkhoinghiep.vn haniamarket.com hanict.org.vn @@ -479388,7 +479434,6 @@ harrisburgprinting.com harriscustomcatering.com harrisheatpumps.nz harrisnewtech.ir -harrisoncarter.com harrisonlily.co.uk harryfang.com harryhiggins.com @@ -482189,7 +482234,6 @@ i-sharecloud.com i-supportcharity.com i-vnsweyu.pl i-voda.com -i.fiery.me i.fluffy.cc i.funtourspt.eu i.ooxx.ooo @@ -488570,6 +488614,7 @@ kebunrayabaturraden.id kec-cendana.enrekangkab.go.id kec-wlingi.blitarkab.go.id kecforging.com +kechuahangdidong.com keciorenkoltukyikama.net keckarangdadap.pekalongankab.go.id kecsfila.hu @@ -506373,6 +506418,7 @@ osrsport.com ossandonycia.cl osscaar.com osservatore.betacom.it +ossi4.51cto.com ossianlaw.com osslusturv.com ossoriobouliz.com @@ -509705,6 +509751,7 @@ politinsky.000webhostapp.com politrix.net poliyzsl.host poljimenez.com +polk.k12.ga.us polka32.ru polkapower.com polkolonieb4k.pl @@ -510876,7 +510923,6 @@ professionalshop.in professionalwaiterskollege.org professionelelit.com professorsgallery.com -profetestruec.net profexsystem.com proffessia.ru proffice.com.pl @@ -511254,6 +511300,7 @@ protech.binarybizz.com protech.mn protechcarpetcare.com protechgroup1.com +protect.mimecast-offshore.com protectiadatelor.biz protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org protection.pecol.eu @@ -519360,7 +519407,6 @@ shareallfilesthroughsecureexchangesystem.duckdns.org sharebook.tk sharechautari.com shared-cnd.com -shared.pdffiller.com shareddocuments.ml shareddynamics.com sharedeconomy.eu @@ -524992,6 +525038,7 @@ sup3rc10ud.ga supadom.fr supamidland-my.sharepoint.com supcargo.com +supdate.mediaweb.co.kr super-filtr.ru super-gamezer.com super-industries.co @@ -529610,7 +529657,6 @@ tlcmoto.com tldrbox.top tlextreme.com tlfthelifefactory.com.au -tlgur.com tlkcloudem.com tlktdsfj.sha58.me tlpclient.site @@ -531246,6 +531292,7 @@ tsport88.com tsr-mark.xyz tsredco.telangana.gov.in tsrj.monster +tsrv2.top tst.marineindust.com tstfrigo.com tsugite.youbi.me @@ -532657,6 +532704,7 @@ update-chase.justmoveup.com update-prog.com update-res.100public.com update.5v.pl +update.7h4uk.com update.att.tools update.bracncet.net update.bruss.org.ru @@ -532896,6 +532944,7 @@ url-update.com url-validation-clients.com url.246546.com url.57569.fr.snd52.ch +url2.mailanyone.net url3.mailanyone.net url5459.41southbar.com url675.textilmallorca.com @@ -534294,7 +534343,6 @@ viettrungkhaison.com viettrust-vn.net vietucgroup.org vietup.net -vietvictory.vn vievioparapija.eu view-indonesia.com view-your-website.com @@ -534748,6 +534796,7 @@ visual-sounds.com visualblends.com visualdata.ru visualdimensioniq.com +visualdive.com visualendodontics.net visualgag.co.uk visualhome.cl @@ -535826,7 +535875,6 @@ wc2018.top wc3prince.ru wcare.nl wcbgroup.co.uk -wcdownloadercdn.lavasoft.com wcdr.pbas.es wcf-old.sibcat.info wcfamlaw.com @@ -537492,6 +537540,7 @@ workingin-my.sharepoint.com workingonit.site workingpainters.com workingroofers.com +workingsolutionsrome.org workingwell.club worklinic.com.br workmate-sien.com @@ -539858,7 +539907,6 @@ yoyoplease.com yoyoso.nz yoyoteacher.cn yp.dcyazilim.com -yp.hnggzyjy.cn ypbb.or.id ypddf.org ypicsdy.cf @@ -540807,6 +540855,7 @@ zoovetdv.ru zoox.com.br zoparo.nl zopbxtjiuykhyyp.usa.cc +zopro.duckdns.org zoracle.com zorancreative.com zoratech.ro diff --git a/urlhaus-filter-hosts-online.txt b/urlhaus-filter-hosts-online.txt index 2fc698f8..e4b8e366 100644 --- a/urlhaus-filter-hosts-online.txt +++ b/urlhaus-filter-hosts-online.txt @@ -1,5 +1,5 @@ # Title: Online Malicious Hosts Blocklist -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -16,7 +16,6 @@ 0.0.0.0 360down7.miiyun.cn 0.0.0.0 77st.net 0.0.0.0 8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com -0.0.0.0 87du.vip 0.0.0.0 8poieq.bn.files.1drv.com 0.0.0.0 aatreefelling.co.za 0.0.0.0 abad.tv @@ -77,6 +76,7 @@ 0.0.0.0 anantam.net.in 0.0.0.0 andreelapeyre.com 0.0.0.0 andremaraisbeleggings.co.za +0.0.0.0 andreonemaia.com 0.0.0.0 andres.ac.ug 0.0.0.0 andres.ug 0.0.0.0 andreshconcejal.solucioneslink.com @@ -86,7 +86,6 @@ 0.0.0.0 anhung1102.vn 0.0.0.0 anurontv.com 0.0.0.0 anysbergbiltong.co.za -0.0.0.0 apartamentoscitta.com 0.0.0.0 api-ms.cobainaja.id 0.0.0.0 api.cstdevs.com 0.0.0.0 api.quocbao.biz @@ -109,15 +108,17 @@ 0.0.0.0 attach.66rpg.com 0.0.0.0 atteuqpotentialunlimited.com 0.0.0.0 augustair.com +0.0.0.0 aulist.com +0.0.0.0 automaticrefreshments.com 0.0.0.0 avadhanagames.com 0.0.0.0 ayahuascasp.com.br 0.0.0.0 ayamallah.com +0.0.0.0 aycconsultoriaempresarial.com 0.0.0.0 azmeasurement.com 0.0.0.0 b2b.toptanakaryakit.com.tr 0.0.0.0 backgrounds.pk 0.0.0.0 badeggdesign.com 0.0.0.0 balealgodon.mx -0.0.0.0 ballina.andrewmaughan.com 0.0.0.0 bangkok-orchids.com 0.0.0.0 bangladeshunbound.com 0.0.0.0 bary.sz4h.com @@ -128,6 +129,7 @@ 0.0.0.0 bcmt.elin.co.za 0.0.0.0 bcrg.co.za 0.0.0.0 bdnextrend.xyz +0.0.0.0 beanx88.xyz 0.0.0.0 bearcatpumps.com.cn 0.0.0.0 beautincollagen.rs 0.0.0.0 bekape.co.id @@ -135,6 +137,7 @@ 0.0.0.0 bespokeweddings.ie 0.0.0.0 bestcarenepal.com 0.0.0.0 betone.co.kr +0.0.0.0 betycopaints.com 0.0.0.0 beveragesmiami.solucioneslink.com 0.0.0.0 bhavaniengineering.com 0.0.0.0 bigmikesupplies.co.za @@ -163,6 +166,7 @@ 0.0.0.0 bounces.mi-fs.com 0.0.0.0 boutiqueofferte.com 0.0.0.0 bpo.correct.go.th +0.0.0.0 bradleyinstitute.co.za 0.0.0.0 brandtrust.com.pk 0.0.0.0 braunfinancial.com.au 0.0.0.0 brendanquine.com @@ -213,6 +217,7 @@ 0.0.0.0 childselect.com 0.0.0.0 chinhdropfile.myvnc.com 0.0.0.0 chinhdropfile80.myvnc.com +0.0.0.0 chipmania.it 0.0.0.0 cible-energy.com 0.0.0.0 cifeer.net 0.0.0.0 cirugiadenarizbucaramanga.com @@ -226,10 +231,9 @@ 0.0.0.0 cm-arquitetos.com 0.0.0.0 codsambal.com 0.0.0.0 colempaques.info -0.0.0.0 colinde.pricesne.com 0.0.0.0 colorpak.pl +0.0.0.0 columbia.aula-web.net 0.0.0.0 community.reimclub.com -0.0.0.0 comosairdoburaco.com.br 0.0.0.0 competancy.indigoconsult.net 0.0.0.0 conceptimagine.ro 0.0.0.0 config.cqhbkjzx.com @@ -245,7 +249,6 @@ 0.0.0.0 cpanel.shivay.net 0.0.0.0 cr-sq.com 0.0.0.0 craftech.nxtnet.ga -0.0.0.0 crearechile.cl 0.0.0.0 creationskateboards.com 0.0.0.0 crecerco.com 0.0.0.0 crittersbythebay.com @@ -255,7 +258,6 @@ 0.0.0.0 crscorretordeimoveis.com.br 0.0.0.0 cse-engineer.com 0.0.0.0 csnserver.com -0.0.0.0 ctracknxt.in 0.0.0.0 cubescargoexpress.com 0.0.0.0 curasoles.co.za 0.0.0.0 currantmedia.com @@ -274,7 +276,6 @@ 0.0.0.0 data.over-blog-kiwi.com 0.0.0.0 datapolish.com 0.0.0.0 dating.khokhas.co.za -0.0.0.0 datsom.vn 0.0.0.0 davethompson.me.uk 0.0.0.0 davidmcguinness.info 0.0.0.0 dayspringdaisies.com @@ -298,7 +299,6 @@ 0.0.0.0 detorre.es 0.0.0.0 dev.sebpo.net 0.0.0.0 dev.watch-store.eu -0.0.0.0 dezcom.com 0.0.0.0 dfcf.91756.cn 0.0.0.0 dfsfcsfcdsfsdvcfsvcscv.com 0.0.0.0 diamantenegro.mi-fs.com @@ -313,6 +313,7 @@ 0.0.0.0 dl.packetstormsecurity.net 0.0.0.0 dl.rina-roleplay.com 0.0.0.0 dnn.alibuf.com +0.0.0.0 dns.alibuf.com 0.0.0.0 dns.cyberium.cc 0.0.0.0 dockerupdate.anondns.net 0.0.0.0 docman.orientalservices.in @@ -329,6 +330,8 @@ 0.0.0.0 dosman.pl 0.0.0.0 dovberger.com 0.0.0.0 down.pcclear.com +0.0.0.0 down.postch-de.top +0.0.0.0 down.postch-dl.top 0.0.0.0 down.udashi.com 0.0.0.0 down.webbora.com 0.0.0.0 down1.arpun.com @@ -388,14 +391,13 @@ 0.0.0.0 f1sol.com 0.0.0.0 fahrzeugdrive.com 0.0.0.0 familydentist.site -0.0.0.0 faveraprojects.com 0.0.0.0 fc.co.mz 0.0.0.0 felicienne.nl 0.0.0.0 files.martellexpress.us 0.0.0.0 filmotainment.com 0.0.0.0 final.makkahkmcc.com 0.0.0.0 fineartgallerym.com -0.0.0.0 fisconline.casa +0.0.0.0 fisconline.bar 0.0.0.0 fix-america-now.org 0.0.0.0 fixauto.illumetechnology.com 0.0.0.0 fixturegovernment.com @@ -410,7 +412,6 @@ 0.0.0.0 footweardirect.elin.co.za 0.0.0.0 forum.mdb.nu 0.0.0.0 fotoobjetivo.com -0.0.0.0 foundationrepairhoustontx.net 0.0.0.0 foxeps.com.br 0.0.0.0 fraud.bpcbankingtech.com 0.0.0.0 freecnetdownload.com @@ -419,7 +420,6 @@ 0.0.0.0 fullelectronica.com.ar 0.0.0.0 funletters.net 0.0.0.0 fusionfiresolutions.com -0.0.0.0 futbolpr.com 0.0.0.0 futuregraphics.com.ar 0.0.0.0 g.pinmonkey.xyz 0.0.0.0 gametwogame.com @@ -436,6 +436,7 @@ 0.0.0.0 ghislain.dartois.pagesperso-orange.fr 0.0.0.0 giadungg7.com 0.0.0.0 giddos.ga +0.0.0.0 giteletropical.com 0.0.0.0 glowinmedia.co.ke 0.0.0.0 gmsebpl.com 0.0.0.0 gmtransformationacademy.com @@ -448,6 +449,7 @@ 0.0.0.0 goldcoastoffice365.com.au 0.0.0.0 golden-memories-funerals.yourpageserver.com 0.0.0.0 goldenasiacapital.com +0.0.0.0 goldmen.in 0.0.0.0 gorecycle.fahadjutt.com 0.0.0.0 gpotecnosystems.com 0.0.0.0 gracejukes.com @@ -476,13 +478,12 @@ 0.0.0.0 highlandroadcoc.com 0.0.0.0 highlandslasvegas.atakdev.com 0.0.0.0 hindi.factsriver.com -0.0.0.0 hiptool.net 0.0.0.0 hitpe.com 0.0.0.0 hitstation.nl +0.0.0.0 hlmd.in 0.0.0.0 hmpmall.co.kr 0.0.0.0 hoagietesting10.com 0.0.0.0 hoayeuthuong-my.sharepoint.com -0.0.0.0 holmesservices.mobiledevsite.co 0.0.0.0 homefindersolutions.com 0.0.0.0 hongluosi.com 0.0.0.0 hookedupboatclub.com @@ -493,7 +494,6 @@ 0.0.0.0 hr2019.vrcom7.com 0.0.0.0 hrnautica.com.br 0.0.0.0 hseda.com -0.0.0.0 hsmwebapp.com 0.0.0.0 htownbars.com 0.0.0.0 hubtech.co.za 0.0.0.0 huellacero.cl @@ -533,16 +533,19 @@ 0.0.0.0 ipmes.ma 0.0.0.0 iremart.es 0.0.0.0 iris101.co.uk +0.0.0.0 isaac.mikhailmotoringschool.com 0.0.0.0 iscamenabe.com 0.0.0.0 isiphephelocon.co.za 0.0.0.0 iso-dubai.net 0.0.0.0 israrulhaq.me +0.0.0.0 isrorg.com 0.0.0.0 isso.ps 0.0.0.0 ist-security.com 0.0.0.0 it123.ru 0.0.0.0 italiandirezione.casa 0.0.0.0 itc-demo.softgig.co.ke 0.0.0.0 itelsys.ma +0.0.0.0 itmotasaciones.com 0.0.0.0 jacktech.jackindia.com 0.0.0.0 jaishritours.com 0.0.0.0 jamiekaylive.com @@ -556,6 +559,7 @@ 0.0.0.0 jhayesconsulting.com 0.0.0.0 jiaoyuzixun.cn 0.0.0.0 jing-da.com.tw +0.0.0.0 jmtc.91756.cn 0.0.0.0 jnanbharati.com 0.0.0.0 jobs.thebeessolution.com 0.0.0.0 joelbonissilver.com @@ -566,6 +570,7 @@ 0.0.0.0 jupiter.toxsl.in 0.0.0.0 justinscott.com.au 0.0.0.0 kadigital.co.uk +0.0.0.0 kaizenjanitorial.com 0.0.0.0 kalawatihomes.com 0.0.0.0 kalogirosfinance.com 0.0.0.0 kaptaanchapal.com @@ -627,14 +632,16 @@ 0.0.0.0 lp.definerisco.com 0.0.0.0 lp.difusodesign.com 0.0.0.0 lp.quama.pe -0.0.0.0 ltc.typoten.com +0.0.0.0 luckybrownie.com 0.0.0.0 luminouspneuma.com 0.0.0.0 luxomodels.com 0.0.0.0 m-technics.kz 0.0.0.0 m.estudiomoros.com.ar 0.0.0.0 m.mobilelocalsales.com +0.0.0.0 m.softsharks.com 0.0.0.0 madicon.co.za 0.0.0.0 magianegramagiablancayamarres.com +0.0.0.0 maharaniworld.com 0.0.0.0 mail.bs-eiendomme.co.za 0.0.0.0 mail.golimoapp.com 0.0.0.0 mail.jeffsono.org @@ -660,7 +667,6 @@ 0.0.0.0 maxiquim.cl 0.0.0.0 maxoprint.co.uk 0.0.0.0 maxtox.com.pk -0.0.0.0 maybethescobar.com 0.0.0.0 mbgrm.com 0.0.0.0 mbjtimes.com 0.0.0.0 mbsolutions.ge @@ -691,11 +697,12 @@ 0.0.0.0 michimal2.000webhostapp.com 0.0.0.0 microblading.mirliandias.com.br 0.0.0.0 microcomm-group.com +0.0.0.0 mikhailmotoringschool.com +0.0.0.0 mills-skyla30ec.com 0.0.0.0 mingguanwms.com 0.0.0.0 minuevavida.org 0.0.0.0 mirror.mypage.sk 0.0.0.0 misterson.com -0.0.0.0 mixr.at 0.0.0.0 mkontakt.az 0.0.0.0 mktf.mx 0.0.0.0 mmdx.com @@ -732,6 +739,7 @@ 0.0.0.0 nec-i.com 0.0.0.0 nedkellymyanmar.com 0.0.0.0 nelitrianggraeni.000webhostapp.com +0.0.0.0 nellaimasthanbiryani.com 0.0.0.0 nerve.untergrund.net 0.0.0.0 nettube.com.br 0.0.0.0 networkwheels.co.za @@ -756,7 +764,6 @@ 0.0.0.0 nobius.org 0.0.0.0 nocalnoodle.elin.co.za 0.0.0.0 nomadicbees.com -0.0.0.0 nonnarina.ax 0.0.0.0 notamuzikaletleri.com 0.0.0.0 ns1.the-widyantos.com 0.0.0.0 nsb.org.uk @@ -776,12 +783,15 @@ 0.0.0.0 omega.az 0.0.0.0 oms.pappai.com 0.0.0.0 omscoc.pappai.com +0.0.0.0 onedigitalcard.granvizionnecorp.com 0.0.0.0 onedrive.listifyapp.co 0.0.0.0 online.creedglobal.in 0.0.0.0 onlinestatis.bar +0.0.0.0 open.rawntech.com 0.0.0.0 open.warehousesaas.co.uk 0.0.0.0 opentoronto.org 0.0.0.0 opolis.io +0.0.0.0 opticaoptigral.cl 0.0.0.0 optimus.com.sg 0.0.0.0 order.bizpeed.com 0.0.0.0 orientgatewayltd.com @@ -819,6 +829,7 @@ 0.0.0.0 pd.oceaniarp.net 0.0.0.0 pemdodo.com 0.0.0.0 perfumeriamontes.es +0.0.0.0 periodiche.bar 0.0.0.0 perpus.onlineman7-jombang.sch.id 0.0.0.0 perpustekim.untirta.ac.id 0.0.0.0 pestoclean.co.uk @@ -838,6 +849,7 @@ 0.0.0.0 pointactionsg.com 0.0.0.0 pokojewewladyslawowie.pl 0.0.0.0 pole.com.vc +0.0.0.0 ponchokhana.com 0.0.0.0 pool.phxdir.com 0.0.0.0 pooltablemoversdenver.net 0.0.0.0 portal.premiumpunch.com @@ -848,6 +860,7 @@ 0.0.0.0 prestigehomeautomation.net 0.0.0.0 preview2.behalen.com 0.0.0.0 prishaartcreations.com +0.0.0.0 prismaxis.com 0.0.0.0 production.sparshims.com 0.0.0.0 programaoperadoronline.com.br 0.0.0.0 project.exquitec.com @@ -899,7 +912,6 @@ 0.0.0.0 resuco.net 0.0.0.0 rezkabum.ru 0.0.0.0 rhema.com.sg -0.0.0.0 richancyber.info 0.0.0.0 richmondminerals.co.zm 0.0.0.0 rinaefoundation.org.za 0.0.0.0 rinkaisystem-ht.com @@ -908,7 +920,6 @@ 0.0.0.0 rkverify.securestudies.com 0.0.0.0 robertmcardle.com 0.0.0.0 robertsinclair.net -0.0.0.0 romanianpoints.com 0.0.0.0 ronnietucker.co.uk 0.0.0.0 roomsvc.servegate.kr 0.0.0.0 roshnijewellery.com @@ -918,7 +929,6 @@ 0.0.0.0 ruisgood.ru 0.0.0.0 ruwadalkuwait.com 0.0.0.0 rydchile.cl -0.0.0.0 s.51shijuan.com 0.0.0.0 s.thechinesemuslim.com 0.0.0.0 sac2.11xii.com 0.0.0.0 sacredscentsonline.com @@ -952,7 +962,9 @@ 0.0.0.0 sericaasia.com 0.0.0.0 servicemhkd.myvnc.com 0.0.0.0 servicemhkd80.myvnc.com +0.0.0.0 serviciovirtual.com.ar 0.0.0.0 sexologistpakistan.net +0.0.0.0 seyranikenger.com.tr 0.0.0.0 sgb.ac.ke 0.0.0.0 sgessy.com.br 0.0.0.0 shaheentbfoundation.com @@ -1003,6 +1015,7 @@ 0.0.0.0 special-key.cf 0.0.0.0 spent.com.pl 0.0.0.0 spetsesyachtcharter.gr +0.0.0.0 spiritualroot.org 0.0.0.0 spititourism.com 0.0.0.0 spittinfire.com 0.0.0.0 sports-net.de @@ -1022,7 +1035,7 @@ 0.0.0.0 stlukesohag.com 0.0.0.0 store.ericalgarin.com 0.0.0.0 stott-thompson.co.uk -0.0.0.0 streetdemo.yourpageserver.com +0.0.0.0 stratexec.co.za 0.0.0.0 suboldesign.com 0.0.0.0 sumerians.org 0.0.0.0 sunaryem.com.tr @@ -1070,6 +1083,7 @@ 0.0.0.0 test.typoten.com 0.0.0.0 test.wanepghana.org 0.0.0.0 test1.asistencia247.com +0.0.0.0 test1.milenial.id 0.0.0.0 test1.tenplusone.my 0.0.0.0 test2.basis-web.com 0.0.0.0 test2.marrenconstruction.ie @@ -1094,7 +1108,7 @@ 0.0.0.0 theprofinn.com 0.0.0.0 thesummitpc.net 0.0.0.0 theurbantutors.com -0.0.0.0 thientu.net +0.0.0.0 thirdstringcalifornia.com 0.0.0.0 thosewebbs.com 0.0.0.0 thriveink.com 0.0.0.0 tianangdep.com @@ -1104,7 +1118,6 @@ 0.0.0.0 timegonebuy.com 0.0.0.0 tksb.net 0.0.0.0 tlcc.com.gt -0.0.0.0 tntmedia.gr 0.0.0.0 todoapp.cstdevs.com 0.0.0.0 todocontodo.com.mx 0.0.0.0 tonydong.com @@ -1141,6 +1154,7 @@ 0.0.0.0 umwelt-kirchhof.de 0.0.0.0 unicorpbrunei.com 0.0.0.0 uniengrisb.com +0.0.0.0 unisoftcc.com 0.0.0.0 unyazitelecom.com 0.0.0.0 upcbpta.com 0.0.0.0 urbantrapfest.cl @@ -1155,7 +1169,9 @@ 0.0.0.0 vcah.co.uk 0.0.0.0 vectarts.com 0.0.0.0 vegadelcasero.cl +0.0.0.0 velma-harber30ku.com 0.0.0.0 vendas.lidiacarmeli.com.br +0.0.0.0 versualstudio.com 0.0.0.0 veterinariadrpopui.com 0.0.0.0 vfocus.net 0.0.0.0 vienen.gblix.srv.br @@ -1182,6 +1198,7 @@ 0.0.0.0 w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu 0.0.0.0 wanepliberia.org 0.0.0.0 wanepniger.org +0.0.0.0 weareactum.com 0.0.0.0 web.eng.ubu.ac.th 0.0.0.0 web.geetle.ga 0.0.0.0 web.geomegasoft.net @@ -1209,6 +1226,7 @@ 0.0.0.0 wonderhawaii.com 0.0.0.0 woodsytech.com 0.0.0.0 wordpress.saleensuporte.com.br +0.0.0.0 workingsolutionsrome.org 0.0.0.0 wozata.000webhostapp.com 0.0.0.0 wp.readhere.in 0.0.0.0 wpdemo.101clients.com.au @@ -1230,7 +1248,6 @@ 0.0.0.0 yourclub1.com 0.0.0.0 yourtopdog.com.au 0.0.0.0 youtubetrainingacademy.com -0.0.0.0 yp.hnggzyjy.cn 0.0.0.0 yskadvisors.com 0.0.0.0 yummyyogaudaipur.com 0.0.0.0 yzkzixun.com diff --git a/urlhaus-filter-hosts.txt b/urlhaus-filter-hosts.txt index c3a26322..f17df37f 100644 --- a/urlhaus-filter-hosts.txt +++ b/urlhaus-filter-hosts.txt @@ -1,5 +1,5 @@ # Title: Malicious Hosts Blocklist -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -238,7 +238,6 @@ 0.0.0.0 123moviesfx.com 0.0.0.0 123sellfast.com 0.0.0.0 123sex.co -0.0.0.0 123tadi.com 0.0.0.0 123xyz.xyz 0.0.0.0 124.com.ua 0.0.0.0 124.cpanel.realwebsitesite.com @@ -7094,7 +7093,6 @@ 0.0.0.0 app.boxrcdn.com 0.0.0.0 app.bridgeimpex.org 0.0.0.0 app.calag.at -0.0.0.0 app.casetabs.com 0.0.0.0 app.catholicchurch.co.in 0.0.0.0 app.choiphui.com 0.0.0.0 app.cloudindustry.net @@ -11326,6 +11324,7 @@ 0.0.0.0 beansmedia.com 0.0.0.0 beanssur.com 0.0.0.0 beantreefoods.com +0.0.0.0 beanx88.xyz 0.0.0.0 beanz-network.com 0.0.0.0 bearcatpumps.com.cn 0.0.0.0 beard-companies.com @@ -17627,7 +17626,6 @@ 0.0.0.0 cdndownloadlp.club 0.0.0.0 cdnmultimedia.com 0.0.0.0 cdnpic.mgyun.com -0.0.0.0 cdnrep.reimageplus.com 0.0.0.0 cdnxh.net 0.0.0.0 cdoconsult.com.br 0.0.0.0 cdolechon.com @@ -18370,7 +18368,6 @@ 0.0.0.0 cheapgadgets-gq.000webhostapp.com 0.0.0.0 cheapistan.pk 0.0.0.0 cheapmlbjerseysmarlins.com -0.0.0.0 cheapmusic.info 0.0.0.0 cheapoakleysunglasses.net 0.0.0.0 cheappigeontraps.com 0.0.0.0 cheapraccoontraps.com @@ -18419,7 +18416,6 @@ 0.0.0.0 cheematransxpressinc.com 0.0.0.0 cheerchile.cl 0.0.0.0 cheerfulgiversneverlack.com -0.0.0.0 cheerfullydo.com 0.0.0.0 cheesecakery.com.br 0.0.0.0 cheetahridge.mediadevstaging.com 0.0.0.0 chef-solutions.dreamscape.co.in @@ -18858,6 +18854,7 @@ 0.0.0.0 christinablunsum.com 0.0.0.0 christinailoveyousomuchyoumyheart.duckdns.org 0.0.0.0 christinalenway.com +0.0.0.0 christinekeller.ch 0.0.0.0 christinelebeck.com 0.0.0.0 christinmunsch.com 0.0.0.0 christmasatredeemer.org @@ -24428,6 +24425,7 @@ 0.0.0.0 demo.jrkcompany.com 0.0.0.0 demo.kalapifoods.com 0.0.0.0 demo.kanapebudapest.hu +0.0.0.0 demo.kechuahangdidong.com 0.0.0.0 demo.kzonetechnologies.com 0.0.0.0 demo.lamppostmedia.in 0.0.0.0 demo.lapizblanco.com @@ -26492,7 +26490,6 @@ 0.0.0.0 dl-675423.store-downloads.com 0.0.0.0 dl-80076342.md-downloads.com 0.0.0.0 dl-97674424.md-downloads.com -0.0.0.0 dl-gameplayer.dmm.com 0.0.0.0 dl-link.link 0.0.0.0 dl-link.live 0.0.0.0 dl-link.network @@ -26523,7 +26520,6 @@ 0.0.0.0 dl.rina-roleplay.com 0.0.0.0 dl.river-store.com 0.0.0.0 dl.rp-soft.ir -0.0.0.0 dl.softservers.net 0.0.0.0 dl.svcupdate.com 0.0.0.0 dl.teeqee.com 0.0.0.0 dl.x420.me @@ -27326,8 +27322,10 @@ 0.0.0.0 down.post-gg.top 0.0.0.0 down.postch-b.top 0.0.0.0 down.postch-bsw.top +0.0.0.0 down.postch-de.top 0.0.0.0 down.postch-dfa.top 0.0.0.0 down.postch-dj.top +0.0.0.0 down.postch-dl.top 0.0.0.0 down.postch-fa.top 0.0.0.0 down.postch-fj.top 0.0.0.0 down.postch-kf.top @@ -29138,7 +29136,6 @@ 0.0.0.0 economiadigital.biz 0.0.0.0 economika.com.ve 0.0.0.0 economizei.shop -0.0.0.0 economplast.com 0.0.0.0 economywindowcleaner.com 0.0.0.0 econoteen.fea.usp.br 0.0.0.0 econotel.us @@ -33847,7 +33844,6 @@ 0.0.0.0 files.dropmybin.me 0.0.0.0 files.enjin.com 0.0.0.0 files.gathercdn.com -0.0.0.0 files.hrloo.com 0.0.0.0 files.l-d.tech 0.0.0.0 files.martellexpress.us 0.0.0.0 files.mirai-2viv.vn @@ -36060,6 +36056,7 @@ 0.0.0.0 fv1-2.failiem.lv 0.0.0.0 fv13.failiem.lv 0.0.0.0 fv15.failiem.lv +0.0.0.0 fv2-2.failiem.lv 0.0.0.0 fv2-7.failiem.lv 0.0.0.0 fv3.failiem.lv 0.0.0.0 fv6.failiem.lv @@ -40303,7 +40300,6 @@ 0.0.0.0 hangtrentroi.com 0.0.0.0 hangulcafes.ga 0.0.0.0 hanh.cz -0.0.0.0 hanhtrinhtamlinh.com 0.0.0.0 hanhtrinhthanhnienkhoinghiep.vn 0.0.0.0 haniamarket.com 0.0.0.0 hanict.org.vn @@ -40498,7 +40494,6 @@ 0.0.0.0 harriscustomcatering.com 0.0.0.0 harrisheatpumps.nz 0.0.0.0 harrisnewtech.ir -0.0.0.0 harrisoncarter.com 0.0.0.0 harrisonlily.co.uk 0.0.0.0 harryfang.com 0.0.0.0 harryhiggins.com @@ -43299,7 +43294,6 @@ 0.0.0.0 i-supportcharity.com 0.0.0.0 i-vnsweyu.pl 0.0.0.0 i-voda.com -0.0.0.0 i.fiery.me 0.0.0.0 i.fluffy.cc 0.0.0.0 i.funtourspt.eu 0.0.0.0 i.ooxx.ooo @@ -49680,6 +49674,7 @@ 0.0.0.0 kec-cendana.enrekangkab.go.id 0.0.0.0 kec-wlingi.blitarkab.go.id 0.0.0.0 kecforging.com +0.0.0.0 kechuahangdidong.com 0.0.0.0 keciorenkoltukyikama.net 0.0.0.0 keckarangdadap.pekalongankab.go.id 0.0.0.0 kecsfila.hu @@ -67483,6 +67478,7 @@ 0.0.0.0 ossandonycia.cl 0.0.0.0 osscaar.com 0.0.0.0 osservatore.betacom.it +0.0.0.0 ossi4.51cto.com 0.0.0.0 ossianlaw.com 0.0.0.0 osslusturv.com 0.0.0.0 ossoriobouliz.com @@ -70815,6 +70811,7 @@ 0.0.0.0 politrix.net 0.0.0.0 poliyzsl.host 0.0.0.0 poljimenez.com +0.0.0.0 polk.k12.ga.us 0.0.0.0 polka32.ru 0.0.0.0 polkapower.com 0.0.0.0 polkolonieb4k.pl @@ -71986,7 +71983,6 @@ 0.0.0.0 professionalwaiterskollege.org 0.0.0.0 professionelelit.com 0.0.0.0 professorsgallery.com -0.0.0.0 profetestruec.net 0.0.0.0 profexsystem.com 0.0.0.0 proffessia.ru 0.0.0.0 proffice.com.pl @@ -72364,6 +72360,7 @@ 0.0.0.0 protech.mn 0.0.0.0 protechcarpetcare.com 0.0.0.0 protechgroup1.com +0.0.0.0 protect.mimecast-offshore.com 0.0.0.0 protectiadatelor.biz 0.0.0.0 protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org 0.0.0.0 protection.pecol.eu @@ -80470,7 +80467,6 @@ 0.0.0.0 sharebook.tk 0.0.0.0 sharechautari.com 0.0.0.0 shared-cnd.com -0.0.0.0 shared.pdffiller.com 0.0.0.0 shareddocuments.ml 0.0.0.0 shareddynamics.com 0.0.0.0 sharedeconomy.eu @@ -86099,6 +86095,7 @@ 0.0.0.0 supadom.fr 0.0.0.0 supamidland-my.sharepoint.com 0.0.0.0 supcargo.com +0.0.0.0 supdate.mediaweb.co.kr 0.0.0.0 super-filtr.ru 0.0.0.0 super-gamezer.com 0.0.0.0 super-industries.co @@ -90717,7 +90714,6 @@ 0.0.0.0 tldrbox.top 0.0.0.0 tlextreme.com 0.0.0.0 tlfthelifefactory.com.au -0.0.0.0 tlgur.com 0.0.0.0 tlkcloudem.com 0.0.0.0 tlktdsfj.sha58.me 0.0.0.0 tlpclient.site @@ -92353,6 +92349,7 @@ 0.0.0.0 tsr-mark.xyz 0.0.0.0 tsredco.telangana.gov.in 0.0.0.0 tsrj.monster +0.0.0.0 tsrv2.top 0.0.0.0 tst.marineindust.com 0.0.0.0 tstfrigo.com 0.0.0.0 tsugite.youbi.me @@ -93764,6 +93761,7 @@ 0.0.0.0 update-prog.com 0.0.0.0 update-res.100public.com 0.0.0.0 update.5v.pl +0.0.0.0 update.7h4uk.com 0.0.0.0 update.att.tools 0.0.0.0 update.bracncet.net 0.0.0.0 update.bruss.org.ru @@ -94003,6 +94001,7 @@ 0.0.0.0 url-validation-clients.com 0.0.0.0 url.246546.com 0.0.0.0 url.57569.fr.snd52.ch +0.0.0.0 url2.mailanyone.net 0.0.0.0 url3.mailanyone.net 0.0.0.0 url5459.41southbar.com 0.0.0.0 url675.textilmallorca.com @@ -95401,7 +95400,6 @@ 0.0.0.0 viettrust-vn.net 0.0.0.0 vietucgroup.org 0.0.0.0 vietup.net -0.0.0.0 vietvictory.vn 0.0.0.0 vievioparapija.eu 0.0.0.0 view-indonesia.com 0.0.0.0 view-your-website.com @@ -95855,6 +95853,7 @@ 0.0.0.0 visualblends.com 0.0.0.0 visualdata.ru 0.0.0.0 visualdimensioniq.com +0.0.0.0 visualdive.com 0.0.0.0 visualendodontics.net 0.0.0.0 visualgag.co.uk 0.0.0.0 visualhome.cl @@ -96933,7 +96932,6 @@ 0.0.0.0 wc3prince.ru 0.0.0.0 wcare.nl 0.0.0.0 wcbgroup.co.uk -0.0.0.0 wcdownloadercdn.lavasoft.com 0.0.0.0 wcdr.pbas.es 0.0.0.0 wcf-old.sibcat.info 0.0.0.0 wcfamlaw.com @@ -98599,6 +98597,7 @@ 0.0.0.0 workingonit.site 0.0.0.0 workingpainters.com 0.0.0.0 workingroofers.com +0.0.0.0 workingsolutionsrome.org 0.0.0.0 workingwell.club 0.0.0.0 worklinic.com.br 0.0.0.0 workmate-sien.com @@ -100965,7 +100964,6 @@ 0.0.0.0 yoyoso.nz 0.0.0.0 yoyoteacher.cn 0.0.0.0 yp.dcyazilim.com -0.0.0.0 yp.hnggzyjy.cn 0.0.0.0 ypbb.or.id 0.0.0.0 ypddf.org 0.0.0.0 ypicsdy.cf @@ -101914,6 +101912,7 @@ 0.0.0.0 zoox.com.br 0.0.0.0 zoparo.nl 0.0.0.0 zopbxtjiuykhyyp.usa.cc +0.0.0.0 zopro.duckdns.org 0.0.0.0 zoracle.com 0.0.0.0 zorancreative.com 0.0.0.0 zoratech.ro diff --git a/urlhaus-filter-online.tpl b/urlhaus-filter-online.tpl index a575da5b..c5dfb139 100644 --- a/urlhaus-filter-online.tpl +++ b/urlhaus-filter-online.tpl @@ -1,6 +1,6 @@ msFilterList # Title: Online Malicious Hosts Blocklist (IE) -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -19,7 +19,6 @@ msFilterList -d 360down7.miiyun.cn -d 77st.net -d 8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com --d 87du.vip -d 8poieq.bn.files.1drv.com -d aatreefelling.co.za -d abad.tv @@ -80,6 +79,7 @@ msFilterList -d anantam.net.in -d andreelapeyre.com -d andremaraisbeleggings.co.za +-d andreonemaia.com -d andres.ac.ug -d andres.ug -d andreshconcejal.solucioneslink.com @@ -89,7 +89,6 @@ msFilterList -d anhung1102.vn -d anurontv.com -d anysbergbiltong.co.za --d apartamentoscitta.com -d api-ms.cobainaja.id -d api.cstdevs.com -d api.quocbao.biz @@ -112,15 +111,17 @@ msFilterList -d attach.66rpg.com -d atteuqpotentialunlimited.com -d augustair.com +-d aulist.com +-d automaticrefreshments.com -d avadhanagames.com -d ayahuascasp.com.br -d ayamallah.com +-d aycconsultoriaempresarial.com -d azmeasurement.com -d b2b.toptanakaryakit.com.tr -d backgrounds.pk -d badeggdesign.com -d balealgodon.mx --d ballina.andrewmaughan.com -d bangkok-orchids.com -d bangladeshunbound.com -d bary.sz4h.com @@ -131,6 +132,7 @@ msFilterList -d bcmt.elin.co.za -d bcrg.co.za -d bdnextrend.xyz +-d beanx88.xyz -d bearcatpumps.com.cn -d beautincollagen.rs -d bekape.co.id @@ -138,6 +140,7 @@ msFilterList -d bespokeweddings.ie -d bestcarenepal.com -d betone.co.kr +-d betycopaints.com -d beveragesmiami.solucioneslink.com -d bhavaniengineering.com -d bigmikesupplies.co.za @@ -166,6 +169,7 @@ msFilterList -d bounces.mi-fs.com -d boutiqueofferte.com -d bpo.correct.go.th +-d bradleyinstitute.co.za -d brandtrust.com.pk -d braunfinancial.com.au -d brendanquine.com @@ -216,6 +220,7 @@ msFilterList -d childselect.com -d chinhdropfile.myvnc.com -d chinhdropfile80.myvnc.com +-d chipmania.it -d cible-energy.com -d cifeer.net -d cirugiadenarizbucaramanga.com @@ -229,10 +234,9 @@ msFilterList -d cm-arquitetos.com -d codsambal.com -d colempaques.info --d colinde.pricesne.com -d colorpak.pl +-d columbia.aula-web.net -d community.reimclub.com --d comosairdoburaco.com.br -d competancy.indigoconsult.net -d conceptimagine.ro -d config.cqhbkjzx.com @@ -248,7 +252,6 @@ msFilterList -d cpanel.shivay.net -d cr-sq.com -d craftech.nxtnet.ga --d crearechile.cl -d creationskateboards.com -d crecerco.com -d crittersbythebay.com @@ -258,7 +261,6 @@ msFilterList -d crscorretordeimoveis.com.br -d cse-engineer.com -d csnserver.com --d ctracknxt.in -d cubescargoexpress.com -d curasoles.co.za -d currantmedia.com @@ -277,7 +279,6 @@ msFilterList -d data.over-blog-kiwi.com -d datapolish.com -d dating.khokhas.co.za --d datsom.vn -d davethompson.me.uk -d davidmcguinness.info -d dayspringdaisies.com @@ -301,7 +302,6 @@ msFilterList -d detorre.es -d dev.sebpo.net -d dev.watch-store.eu --d dezcom.com -d dfcf.91756.cn -d dfsfcsfcdsfsdvcfsvcscv.com -d diamantenegro.mi-fs.com @@ -316,6 +316,7 @@ msFilterList -d dl.packetstormsecurity.net -d dl.rina-roleplay.com -d dnn.alibuf.com +-d dns.alibuf.com -d dns.cyberium.cc -d dockerupdate.anondns.net -d docman.orientalservices.in @@ -332,6 +333,8 @@ msFilterList -d dosman.pl -d dovberger.com -d down.pcclear.com +-d down.postch-de.top +-d down.postch-dl.top -d down.udashi.com -d down.webbora.com -d down1.arpun.com @@ -391,14 +394,13 @@ msFilterList -d f1sol.com -d fahrzeugdrive.com -d familydentist.site --d faveraprojects.com -d fc.co.mz -d felicienne.nl -d files.martellexpress.us -d filmotainment.com -d final.makkahkmcc.com -d fineartgallerym.com --d fisconline.casa +-d fisconline.bar -d fix-america-now.org -d fixauto.illumetechnology.com -d fixturegovernment.com @@ -413,7 +415,6 @@ msFilterList -d footweardirect.elin.co.za -d forum.mdb.nu -d fotoobjetivo.com --d foundationrepairhoustontx.net -d foxeps.com.br -d fraud.bpcbankingtech.com -d freecnetdownload.com @@ -422,7 +423,6 @@ msFilterList -d fullelectronica.com.ar -d funletters.net -d fusionfiresolutions.com --d futbolpr.com -d futuregraphics.com.ar -d g.pinmonkey.xyz -d gametwogame.com @@ -439,6 +439,7 @@ msFilterList -d ghislain.dartois.pagesperso-orange.fr -d giadungg7.com -d giddos.ga +-d giteletropical.com -d glowinmedia.co.ke -d gmsebpl.com -d gmtransformationacademy.com @@ -451,6 +452,7 @@ msFilterList -d goldcoastoffice365.com.au -d golden-memories-funerals.yourpageserver.com -d goldenasiacapital.com +-d goldmen.in -d gorecycle.fahadjutt.com -d gpotecnosystems.com -d gracejukes.com @@ -479,13 +481,12 @@ msFilterList -d highlandroadcoc.com -d highlandslasvegas.atakdev.com -d hindi.factsriver.com --d hiptool.net -d hitpe.com -d hitstation.nl +-d hlmd.in -d hmpmall.co.kr -d hoagietesting10.com -d hoayeuthuong-my.sharepoint.com --d holmesservices.mobiledevsite.co -d homefindersolutions.com -d hongluosi.com -d hookedupboatclub.com @@ -496,7 +497,6 @@ msFilterList -d hr2019.vrcom7.com -d hrnautica.com.br -d hseda.com --d hsmwebapp.com -d htownbars.com -d hubtech.co.za -d huellacero.cl @@ -536,16 +536,19 @@ msFilterList -d ipmes.ma -d iremart.es -d iris101.co.uk +-d isaac.mikhailmotoringschool.com -d iscamenabe.com -d isiphephelocon.co.za -d iso-dubai.net -d israrulhaq.me +-d isrorg.com -d isso.ps -d ist-security.com -d it123.ru -d italiandirezione.casa -d itc-demo.softgig.co.ke -d itelsys.ma +-d itmotasaciones.com -d jacktech.jackindia.com -d jaishritours.com -d jamiekaylive.com @@ -559,6 +562,7 @@ msFilterList -d jhayesconsulting.com -d jiaoyuzixun.cn -d jing-da.com.tw +-d jmtc.91756.cn -d jnanbharati.com -d jobs.thebeessolution.com -d joelbonissilver.com @@ -569,6 +573,7 @@ msFilterList -d jupiter.toxsl.in -d justinscott.com.au -d kadigital.co.uk +-d kaizenjanitorial.com -d kalawatihomes.com -d kalogirosfinance.com -d kaptaanchapal.com @@ -630,14 +635,16 @@ msFilterList -d lp.definerisco.com -d lp.difusodesign.com -d lp.quama.pe --d ltc.typoten.com +-d luckybrownie.com -d luminouspneuma.com -d luxomodels.com -d m-technics.kz -d m.estudiomoros.com.ar -d m.mobilelocalsales.com +-d m.softsharks.com -d madicon.co.za -d magianegramagiablancayamarres.com +-d maharaniworld.com -d mail.bs-eiendomme.co.za -d mail.golimoapp.com -d mail.jeffsono.org @@ -663,7 +670,6 @@ msFilterList -d maxiquim.cl -d maxoprint.co.uk -d maxtox.com.pk --d maybethescobar.com -d mbgrm.com -d mbjtimes.com -d mbsolutions.ge @@ -694,11 +700,12 @@ msFilterList -d michimal2.000webhostapp.com -d microblading.mirliandias.com.br -d microcomm-group.com +-d mikhailmotoringschool.com +-d mills-skyla30ec.com -d mingguanwms.com -d minuevavida.org -d mirror.mypage.sk -d misterson.com --d mixr.at -d mkontakt.az -d mktf.mx -d mmdx.com @@ -735,6 +742,7 @@ msFilterList -d nec-i.com -d nedkellymyanmar.com -d nelitrianggraeni.000webhostapp.com +-d nellaimasthanbiryani.com -d nerve.untergrund.net -d nettube.com.br -d networkwheels.co.za @@ -759,7 +767,6 @@ msFilterList -d nobius.org -d nocalnoodle.elin.co.za -d nomadicbees.com --d nonnarina.ax -d notamuzikaletleri.com -d ns1.the-widyantos.com -d nsb.org.uk @@ -779,12 +786,15 @@ msFilterList -d omega.az -d oms.pappai.com -d omscoc.pappai.com +-d onedigitalcard.granvizionnecorp.com -d onedrive.listifyapp.co -d online.creedglobal.in -d onlinestatis.bar +-d open.rawntech.com -d open.warehousesaas.co.uk -d opentoronto.org -d opolis.io +-d opticaoptigral.cl -d optimus.com.sg -d order.bizpeed.com -d orientgatewayltd.com @@ -822,6 +832,7 @@ msFilterList -d pd.oceaniarp.net -d pemdodo.com -d perfumeriamontes.es +-d periodiche.bar -d perpus.onlineman7-jombang.sch.id -d perpustekim.untirta.ac.id -d pestoclean.co.uk @@ -841,6 +852,7 @@ msFilterList -d pointactionsg.com -d pokojewewladyslawowie.pl -d pole.com.vc +-d ponchokhana.com -d pool.phxdir.com -d pooltablemoversdenver.net -d portal.premiumpunch.com @@ -851,6 +863,7 @@ msFilterList -d prestigehomeautomation.net -d preview2.behalen.com -d prishaartcreations.com +-d prismaxis.com -d production.sparshims.com -d programaoperadoronline.com.br -d project.exquitec.com @@ -902,7 +915,6 @@ msFilterList -d resuco.net -d rezkabum.ru -d rhema.com.sg --d richancyber.info -d richmondminerals.co.zm -d rinaefoundation.org.za -d rinkaisystem-ht.com @@ -911,7 +923,6 @@ msFilterList -d rkverify.securestudies.com -d robertmcardle.com -d robertsinclair.net --d romanianpoints.com -d ronnietucker.co.uk -d roomsvc.servegate.kr -d roshnijewellery.com @@ -921,7 +932,6 @@ msFilterList -d ruisgood.ru -d ruwadalkuwait.com -d rydchile.cl --d s.51shijuan.com -d s.thechinesemuslim.com -d sac2.11xii.com -d sacredscentsonline.com @@ -955,7 +965,9 @@ msFilterList -d sericaasia.com -d servicemhkd.myvnc.com -d servicemhkd80.myvnc.com +-d serviciovirtual.com.ar -d sexologistpakistan.net +-d seyranikenger.com.tr -d sgb.ac.ke -d sgessy.com.br -d shaheentbfoundation.com @@ -1006,6 +1018,7 @@ msFilterList -d special-key.cf -d spent.com.pl -d spetsesyachtcharter.gr +-d spiritualroot.org -d spititourism.com -d spittinfire.com -d sports-net.de @@ -1025,7 +1038,7 @@ msFilterList -d stlukesohag.com -d store.ericalgarin.com -d stott-thompson.co.uk --d streetdemo.yourpageserver.com +-d stratexec.co.za -d suboldesign.com -d sumerians.org -d sunaryem.com.tr @@ -1073,6 +1086,7 @@ msFilterList -d test.typoten.com -d test.wanepghana.org -d test1.asistencia247.com +-d test1.milenial.id -d test1.tenplusone.my -d test2.basis-web.com -d test2.marrenconstruction.ie @@ -1097,7 +1111,7 @@ msFilterList -d theprofinn.com -d thesummitpc.net -d theurbantutors.com --d thientu.net +-d thirdstringcalifornia.com -d thosewebbs.com -d thriveink.com -d tianangdep.com @@ -1107,7 +1121,6 @@ msFilterList -d timegonebuy.com -d tksb.net -d tlcc.com.gt --d tntmedia.gr -d todoapp.cstdevs.com -d todocontodo.com.mx -d tonydong.com @@ -1144,6 +1157,7 @@ msFilterList -d umwelt-kirchhof.de -d unicorpbrunei.com -d uniengrisb.com +-d unisoftcc.com -d unyazitelecom.com -d upcbpta.com -d urbantrapfest.cl @@ -1158,7 +1172,9 @@ msFilterList -d vcah.co.uk -d vectarts.com -d vegadelcasero.cl +-d velma-harber30ku.com -d vendas.lidiacarmeli.com.br +-d versualstudio.com -d veterinariadrpopui.com -d vfocus.net -d vienen.gblix.srv.br @@ -1185,6 +1201,7 @@ msFilterList -d w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu -d wanepliberia.org -d wanepniger.org +-d weareactum.com -d web.eng.ubu.ac.th -d web.geetle.ga -d web.geomegasoft.net @@ -1212,6 +1229,7 @@ msFilterList -d wonderhawaii.com -d woodsytech.com -d wordpress.saleensuporte.com.br +-d workingsolutionsrome.org -d wozata.000webhostapp.com -d wp.readhere.in -d wpdemo.101clients.com.au @@ -1233,7 +1251,6 @@ msFilterList -d yourclub1.com -d yourtopdog.com.au -d youtubetrainingacademy.com --d yp.hnggzyjy.cn -d yskadvisors.com -d yummyyogaudaipur.com -d yzkzixun.com diff --git a/urlhaus-filter-online.txt b/urlhaus-filter-online.txt index 4480bdc0..bb192ceb 100644 --- a/urlhaus-filter-online.txt +++ b/urlhaus-filter-online.txt @@ -1,5 +1,5 @@ ! Title: Online Malicious URL Blocklist -! Updated: Sat, 03 Apr 2021 00:13:46 UTC +! Updated: Sat, 03 Apr 2021 12:12:28 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -7,6 +7,7 @@ 0-24bpautomentes.hu 0cl.sldov.ru 1.11.234.99 +1.186.151.219 1.222.196.60 1.245.4.163 1.246.222.107 @@ -16,11 +17,9 @@ 1.246.222.134 1.246.222.138 1.246.222.14 -1.246.222.16 1.246.222.165 1.246.222.20 1.246.222.228 -1.246.222.232 1.246.222.234 1.246.222.237 1.246.222.245 @@ -41,6 +40,7 @@ 1.246.223.103 1.246.223.105 1.246.223.109 +1.246.223.126 1.246.223.127 1.246.223.130 1.246.223.146 @@ -78,12 +78,10 @@ 101.73.131.78 101.75.157.99 101.75.167.213 -101.99.94.15 102.130.115.14 102.141.240.139 103.113.99.79 103.125.218.107 -103.136.82.50 103.141.138.118 103.141.138.12 103.146.174.208 @@ -92,12 +90,11 @@ 103.217.215.21 103.224.200.146 103.224.200.40 -103.227.118.129 +103.237.21.36 103.238.228.4 103.240.249.121 103.4.117.26 103.70.160.51 -103.79.112.254 103.82.98.170 103.84.240.130 103.91.245.12 @@ -142,6 +139,7 @@ 109.124.90.229 109.233.196.232 109.235.7.228 +109.248.58.238 109.86.85.253 109.95.200.102 109.95.200.230 @@ -155,28 +153,27 @@ 110.228.195.46 110.241.119.168 110.248.124.254 +110.248.175.141 110.248.251.194 110.251.10.18 110.253.150.248 110.253.213.198 +110.253.51.112 110.255.101.184 110.255.167.147 110.35.145.127 110.35.208.21 -110.35.221.77 110.35.223.92 110.35.225.24 -110.35.233.147 110.35.235.57 +110.35.249.21 110.35.4.2 110fss.net -111.118.111.207 111.118.41.173 111.118.88.61 111.119.245.114 111.125.67.125 111.165.21.195 -111.165.248.134 111.166.236.191 111.167.151.156 111.170.85.71 @@ -193,22 +190,20 @@ 111.38.103.66 111.38.104.141 111.38.104.15 -111.38.106.128 111.38.106.19 111.38.121.222 111.38.121.223 111.38.121.226 111.38.121.228 111.38.26.243 +111.38.8.81 111.61.52.53 112.111.108.184 -112.111.31.175 112.133.222.151 112.147.92.51 112.159.108.96 112.163.200.217 112.170.124.75 -112.170.233.9 112.186.210.211 112.186.96.252 112.187.91.117 @@ -262,18 +257,15 @@ 112.247.81.173 112.247.82.122 112.248.148.90 -112.248.179.239 112.248.197.164 112.249.109.217 112.249.118.157 112.249.26.129 112.249.79.98 112.250.102.173 -112.250.57.99 112.251.218.210 112.252.136.84 112.252.196.17 -112.252.212.122 112.252.221.244 112.252.239.103 112.254.208.123 @@ -309,7 +301,6 @@ 112.27.124.177 112.27.124.178 112.27.124.179 -112.27.124.71 112.27.127.155 112.27.83.182 112.27.83.23 @@ -334,7 +325,6 @@ 112.30.1.91 112.30.110.31 112.30.110.36 -112.30.110.37 112.30.110.38 112.30.110.41 112.30.110.43 @@ -349,21 +339,23 @@ 112.30.4.136 112.30.4.52 112.31.240.239 -112.31.82.160 112.31.87.98 112.53.224.79 112.65.53.175 +112.72.153.37 +112.72.162.159 112.72.162.49 112.72.162.53 112.72.176.112 112.72.176.84 -112.72.231.35 +112.72.226.202 112.78.45.158 112.80.117.32 112.80.118.16 112.80.127.91 112.80.207.144 112.80.215.101 +112.80.218.56 112.82.146.253 112.82.18.255 112.82.224.139 @@ -381,16 +373,14 @@ 113.231.211.131 113.254.169.251 113.59.128.133 -113.59.136.39 +113.59.133.16 113.59.154.21 113.59.191.47 113.61.204.205 -113.87.174.63 -113.87.175.135 -113.89.42.50 113.89.43.185 113.90.26.136 -114.199.204.37 +114.111.242.3 +114.199.253.235 114.200.154.181 114.224.203.128 114.226.100.56 @@ -398,31 +388,24 @@ 114.229.165.194 114.235.115.236 114.30.54.64 -114.32.237.100 114.79.172.42 115.165.216.112 115.201.38.185 115.42.47.36 -115.48.204.56 115.50.21.56 115.51.125.55 115.52.18.65 -115.55.144.42 -115.55.145.147 115.55.153.194 -115.55.190.144 115.55.60.129 115.56.131.242 115.56.133.96 115.56.144.213 115.56.159.132 -115.56.187.173 115.58.132.140 115.58.165.147 -115.59.240.217 115.59.255.194 115.61.118.201 -115.62.26.39 +115.69.102.84 115.73.3.11 115.92.174.231 116.124.219.2 @@ -431,15 +414,21 @@ 116.211.100.26 116.212.132.119 116.212.142.215 -117.196.49.249 +117.194.166.219 117.196.50.107 117.20.204.138 117.20.204.5 117.20.210.52 +117.20.220.126 117.20.236.14 117.20.243.40 +117.20.247.150 117.200.76.54 -117.26.110.103 +117.202.66.15 +117.202.69.113 +117.213.10.108 +117.213.15.72 +117.248.63.12 117.63.113.146 117.63.195.140 117.63.53.15 @@ -464,12 +453,11 @@ 118.42.125.246 118.43.180.33 118.79.125.92 -118.79.218.157 118.79.50.203 118.79.58.82 -118.79.96.11 118.83.79.43 118.91.24.27 +118.91.41.135 118.99.179.164 118.99.183.235 118.99.239.217 @@ -480,7 +468,6 @@ 119.147.213.57 119.163.93.191 119.164.18.235 -119.164.218.229 119.165.107.93 119.165.163.220 119.165.174.63 @@ -493,8 +480,6 @@ 119.167.26.33 119.177.147.38 119.178.248.123 -119.179.157.219 -119.179.16.149 119.179.170.212 119.179.43.1 119.179.75.8 @@ -503,7 +488,6 @@ 119.180.108.227 119.180.108.79 119.180.33.161 -119.180.94.80 119.181.119.21 119.181.124.203 119.182.97.232 @@ -523,12 +507,12 @@ 119.251.105.221 119.251.14.251 119.56.131.155 +119.56.140.73 119.56.143.46 119.56.143.71 119.56.144.75 119.56.148.115 119.56.155.57 -119.56.172.28 119.56.175.41 119.56.195.90 119.56.206.43 @@ -559,22 +543,17 @@ 120.193.91.212 120.193.91.215 120.193.91.233 -120.209.121.243 120.209.126.206 120.209.126.240 120.209.127.187 120.209.99.127 120.210.89.79 120.43.33.202 -120.5.15.95 120.50.66.60 120.50.93.115 -120.6.141.142 120.6.8.11 120.7.75.99 120.85.173.168 -120.85.174.3 -120.85.210.232 121.100.114.164 121.100.96.8 121.121.44.222 @@ -595,10 +574,8 @@ 121.237.226.202 121.239.15.74 121.24.116.173 -121.25.101.86 121.254.43.215 121.254.76.17 -121.61.101.125 121.61.98.151 121.88.99.236 122.100.150.204 @@ -609,7 +586,6 @@ 122.199.66.28 122.199.72.23 122.199.79.27 -122.199.83.86 122.202.37.85 122.202.41.23 122.254.29.37 @@ -626,28 +602,26 @@ 123.128.133.91 123.129.84.36 123.130.208.52 -123.130.23.110 123.130.27.19 123.130.37.182 -123.130.61.210 -123.130.77.225 123.131.186.250 123.132.219.147 123.133.125.77 123.133.98.135 123.134.14.130 123.134.50.186 -123.14.120.130 123.14.199.130 +123.14.248.210 123.153.80.178 123.154.116.116 123.154.236.114 123.154.94.1 123.156.136.21 +123.159.68.119 123.159.8.100 123.183.121.60 -123.191.150.147 123.191.164.92 +123.191.62.239 123.192.101.163 123.192.194.233 123.193.149.235 @@ -672,13 +646,10 @@ 123.241.148.58 123.241.184.124 123.28.217.23 -123.5.189.116 123.5.5.242 -123.8.184.82 124.119.108.87 124.129.221.150 124.129.76.230 -124.130.110.167 124.130.40.31 124.131.104.82 124.131.151.135 @@ -691,7 +662,6 @@ 124.153.136.175 124.153.236.6 124.160.126.238 -124.163.163.193 124.163.65.64 124.163.72.102 124.165.123.7 @@ -715,8 +685,6 @@ 125.40.75.22 125.41.215.9 125.43.53.9 -125.45.63.67 -125.46.129.159 125.79.200.104 128.116.133.92 130.255.159.133 @@ -728,10 +696,12 @@ 139.216.102.151 139.227.46.137 14.102.17.222 +14.102.97.204 14.136.80.242 14.138.8.51 -14.178.163.235 +14.160.34.50 14.189.247.118 +14.241.227.216 14.37.222.190 14.45.127.110 14.46.25.17 @@ -758,23 +728,19 @@ 153.101.47.145 153.3.152.106 153.34.135.92 -153.36.126.35 155.138.134.44 158.101.165.14 158.174.213.128 -158.247.195.165 158.51.125.115 159.224.74.112 162.194.28.60 162.209.98.174 163.53.206.228 165.90.16.5 -168.205.223.254 170.81.238.178 171.113.36.216 171.113.38.107 171.121.255.10 -171.34.112.42 171.34.114.181 171.34.176.217 171.34.179.178 @@ -784,6 +750,7 @@ 172.114.244.127 172.245.5.185 172.245.5.190 +172.245.79.106 172.245.81.19 172.93.194.114 173.167.85.89 @@ -810,7 +777,6 @@ 175.169.13.182 175.201.104.192 175.208.230.8 -175.212.6.169 175.42.46.118 175.9.24.110 175.9.90.89 @@ -822,7 +788,6 @@ 176.111.174.67 176.113.161.104 176.113.161.113 -176.113.161.138 176.113.161.60 176.113.161.65 176.113.161.66 @@ -836,7 +801,7 @@ 176.123.7.127 176.123.9.243 176.124.7.225 -176.221.242.166 +176.221.188.251 176.240.84.106 177.11.92.78 177.131.226.235 @@ -846,35 +811,31 @@ 178.124.182.187 178.141.142.15 178.150.174.65 +178.151.143.2 178.165.122.141 178.175.0.200 178.175.1.137 -178.175.1.153 178.175.1.179 178.175.1.248 178.175.1.249 178.175.1.250 178.175.1.44 178.175.1.80 +178.175.100.151 +178.175.100.7 178.175.101.110 178.175.101.232 -178.175.102.133 178.175.102.171 178.175.102.67 178.175.103.98 -178.175.104.145 178.175.104.155 178.175.104.69 -178.175.105.125 178.175.105.95 -178.175.106.118 178.175.106.193 -178.175.106.201 178.175.107.0 178.175.107.245 178.175.107.83 178.175.108.105 -178.175.108.149 178.175.108.87 178.175.109.129 178.175.109.26 @@ -886,23 +847,19 @@ 178.175.111.206 178.175.112.135 178.175.112.139 +178.175.112.140 178.175.112.147 178.175.112.159 178.175.112.46 178.175.112.58 -178.175.113.27 178.175.114.114 -178.175.114.63 178.175.115.110 178.175.115.209 178.175.116.101 178.175.116.138 -178.175.116.168 -178.175.116.90 178.175.117.30 178.175.118.112 178.175.118.146 -178.175.118.210 178.175.119.102 178.175.119.114 178.175.119.69 @@ -923,18 +880,15 @@ 178.175.123.248 178.175.123.26 178.175.123.30 -178.175.123.48 178.175.123.91 178.175.124.131 178.175.124.155 178.175.124.4 -178.175.124.79 178.175.125.14 178.175.125.160 178.175.125.220 178.175.125.88 178.175.126.129 -178.175.126.153 178.175.126.252 178.175.126.46 178.175.127.202 @@ -944,7 +898,6 @@ 178.175.13.254 178.175.15.199 178.175.15.215 -178.175.15.35 178.175.16.108 178.175.16.116 178.175.16.251 @@ -953,20 +906,17 @@ 178.175.17.118 178.175.17.61 178.175.18.23 +178.175.18.37 178.175.18.75 178.175.19.163 178.175.19.174 178.175.19.91 -178.175.2.118 -178.175.2.123 178.175.2.209 178.175.2.5 178.175.20.117 178.175.20.70 178.175.20.97 178.175.21.149 -178.175.21.184 -178.175.21.238 178.175.22.237 178.175.23.144 178.175.23.176 @@ -978,7 +928,6 @@ 178.175.25.56 178.175.26.215 178.175.27.114 -178.175.27.127 178.175.27.171 178.175.27.213 178.175.27.32 @@ -986,18 +935,17 @@ 178.175.27.46 178.175.28.239 178.175.28.47 -178.175.29.2 178.175.29.21 178.175.3.172 178.175.3.214 178.175.30.133 178.175.30.151 178.175.30.213 -178.175.31.251 178.175.31.73 178.175.32.146 178.175.32.220 178.175.32.89 +178.175.33.162 178.175.33.7 178.175.34.217 178.175.34.247 @@ -1014,11 +962,12 @@ 178.175.4.144 178.175.4.72 178.175.40.136 -178.175.40.166 178.175.40.228 178.175.42.101 178.175.42.6 178.175.43.121 +178.175.43.223 +178.175.43.229 178.175.43.238 178.175.43.244 178.175.44.0 @@ -1031,13 +980,11 @@ 178.175.45.26 178.175.46.129 178.175.46.137 -178.175.46.243 178.175.46.41 178.175.46.42 178.175.46.8 178.175.47.143 178.175.48.51 -178.175.49.12 178.175.5.57 178.175.50.10 178.175.50.177 @@ -1056,10 +1003,8 @@ 178.175.56.82 178.175.56.87 178.175.57.134 -178.175.57.179 178.175.58.183 178.175.58.79 -178.175.59.131 178.175.59.33 178.175.6.115 178.175.6.140 @@ -1071,15 +1016,12 @@ 178.175.60.209 178.175.60.212 178.175.60.221 -178.175.61.235 -178.175.62.232 178.175.62.70 178.175.62.81 178.175.63.21 178.175.64.156 178.175.66.186 178.175.66.192 -178.175.66.211 178.175.68.116 178.175.68.123 178.175.68.209 @@ -1088,60 +1030,51 @@ 178.175.69.153 178.175.69.67 178.175.7.105 -178.175.7.107 178.175.7.14 -178.175.7.21 178.175.7.35 178.175.7.60 178.175.7.79 -178.175.70.212 178.175.70.218 +178.175.71.179 178.175.72.222 178.175.72.65 -178.175.73.42 178.175.75.181 178.175.75.244 -178.175.77.248 -178.175.77.46 178.175.77.47 178.175.78.169 178.175.78.2 -178.175.8.181 +178.175.78.242 178.175.80.89 -178.175.81.176 178.175.81.226 -178.175.81.235 178.175.81.31 178.175.83.2 +178.175.83.247 178.175.84.215 -178.175.84.61 178.175.85.23 178.175.85.53 178.175.86.59 178.175.87.146 178.175.87.42 178.175.87.91 -178.175.88.166 178.175.88.4 +178.175.89.121 178.175.89.217 178.175.89.6 178.175.9.179 178.175.9.198 178.175.9.4 -178.175.90.81 +178.175.90.4 178.175.92.1 178.175.92.102 178.175.92.92 178.175.93.143 -178.175.94.182 178.175.94.27 178.175.94.32 178.175.94.40 178.175.94.61 178.175.95.120 -178.175.96.218 178.175.96.251 -178.175.97.14 +178.175.97.113 178.175.98.83 178.175.99.120 178.175.99.130 @@ -1154,7 +1087,6 @@ 178.222.252.130 178.34.183.30 178.48.235.59 -178.72.91.172 178.95.136.35 179.159.58.134 179.60.84.7 @@ -1163,7 +1095,6 @@ 180.116.203.220 180.122.13.227 180.123.208.250 -180.125.44.194 180.157.66.204 180.175.236.209 180.176.105.41 @@ -1199,30 +1130,20 @@ 182.116.61.252 182.116.99.150 182.117.43.185 -182.117.43.82 182.119.120.8 182.119.164.128 -182.119.200.62 182.119.202.130 182.120.16.22 182.120.16.46 -182.121.127.106 -182.123.205.157 -182.123.211.239 -182.124.138.54 -182.126.121.211 +182.121.26.37 182.127.152.3 182.160.98.250 182.233.0.252 182.235.252.31 182.53.197.62 -183.105.104.83 183.105.225.154 183.109.169.45 183.128.152.115 -183.144.9.97 -183.185.112.19 -183.83.18.203 183.83.29.191 183.92.207.147 184.164.185.41 @@ -1249,7 +1170,6 @@ 185.68.230.207 185.81.157.186 185.82.217.185 -185.82.217.213 185.82.219.160 185.82.219.161 185.82.219.219 @@ -1268,7 +1188,6 @@ 187.12.10.98 187.188.124.229 187.212.200.162 -187.85.244.145 188.10.21.14 188.10.231.246 188.113.81.17 @@ -1277,6 +1196,8 @@ 188.143.220.152 188.152.41.141 188.169.178.50 +188.169.179.127 +188.169.199.59 188.242.242.144 188.81.100.83 188.83.202.25 @@ -1316,7 +1237,6 @@ 192.227.185.106 192.227.209.27 192.227.220.55 -192.227.223.96 192.227.228.67 192.227.230.74 192.3.152.166 @@ -1350,7 +1270,6 @@ 1am.co.nz 2.229.89.119 2.239.22.188 -2.249.161.188 2.37.149.230 2.37.203.65 2.45.4.24 @@ -1359,7 +1278,6 @@ 2.57.122.107 2.83.152.16 20.185.42.197 -200.104.150.167 200.105.167.98 200.111.189.70 200.194.4.24 @@ -1370,11 +1288,10 @@ 201.184.163.170 201.187.102.73 201.200.254.86 +201.203.221.20 201.203.27.37 -201.205.12.170 202.107.233.41 202.150.176.100 -202.166.217.54 202.175.103.10 202.29.95.12 202.4.124.58 @@ -1387,7 +1304,6 @@ 203.229.21.56 203.236.190.28 203.238.86.202 -203.243.142.132 203.70.166.107 203.77.80.159 203.80.119.166 @@ -1397,7 +1313,6 @@ 204.195.116.171 205.185.115.74 205.185.116.94 -205.185.123.217 206.248.137.132 206.47.41.166 207.180.228.101 @@ -1407,8 +1322,8 @@ 209.141.39.50 209.141.40.190 209.141.40.31 -209.141.46.87 210.124.149.19 +210.180.17.140 210.216.152.122 210.216.153.142 210.57.234.93 @@ -1419,7 +1334,6 @@ 211.116.220.37 211.187.132.204 211.187.75.220 -211.200.160.239 211.204.215.157 211.210.66.179 211.210.93.93 @@ -1437,31 +1351,31 @@ 212.46.197.114 212.56.197.230 212.8.251.211 +212.8.251.227 213.123.206.197 213.135.178.253 213.14.173.117 213.149.182.113 213.149.190.193 -213.163.104.12 213.163.104.99 213.163.113.135 213.163.113.20 213.163.113.237 213.163.113.6 213.163.114.165 +213.163.114.191 213.163.115.105 213.163.115.11 213.163.115.15 213.163.115.30 213.163.115.71 -213.163.116.192 213.163.117.151 +213.163.118.10 213.163.118.238 213.163.118.65 213.163.119.236 -213.163.126.175 +213.163.126.145 213.163.126.7 -213.163.127.107 213.163.127.46 213.189.178.163 213.240.218.15 @@ -1476,32 +1390,26 @@ 216.183.54.169 216.36.12.98 217.11.75.162 +217.127.133.214 218.12.181.110 218.2.40.34 218.234.165.18 218.238.246.3 -218.28.160.174 218.35.207.119 218.35.227.133 218.35.68.35 218.35.81.81 218.56.93.129 -218.58.92.253 218.59.116.203 -218.72.207.116 218.79.103.159 218.93.102.63 218.93.102.75 219.155.102.14 -219.155.11.207 -219.155.12.85 -219.155.26.190 219.155.29.165 219.156.186.18 219.157.139.165 219.157.150.91 219.157.214.235 -219.157.50.106 219.241.6.180 219.68.1.148 219.68.1.84 @@ -1510,19 +1418,17 @@ 219.68.245.63 219.68.5.140 219.69.71.186 +219.70.238.66 219.80.217.209 219.85.145.194 21robo.com 220.118.168.155 220.126.237.74 220.200.22.163 -220.247.91.17 220.71.239.115 -220.90.159.188 221.1.144.183 221.124.78.15 -221.15.113.234 -221.157.191.178 +221.15.125.69 221.160.136.213 221.202.232.230 221.214.130.147 @@ -1544,16 +1450,15 @@ 222.119.65.145 222.132.125.138 222.133.103.120 -222.135.67.115 222.135.9.5 222.137.148.192 222.137.211.78 222.138.17.132 222.138.237.155 222.140.17.245 -222.162.187.43 222.179.215.189 222.185.116.233 +222.186.20.19 222.187.9.178 222.211.72.66 222.236.85.220 @@ -1604,6 +1509,7 @@ 27.105.106.201 27.105.152.107 27.116.84.57 +27.14.211.219 27.14.81.201 27.141.218.17 27.147.29.52 @@ -1647,8 +1553,6 @@ 27.207.155.31 27.207.170.203 27.208.119.27 -27.208.152.10 -27.208.160.177 27.208.164.18 27.208.237.105 27.208.247.130 @@ -1658,13 +1562,13 @@ 27.209.208.122 27.209.231.15 27.210.107.125 -27.210.172.245 27.210.234.28 27.210.236.134 +27.210.32.122 27.210.44.19 27.210.63.243 27.213.104.201 -27.213.109.58 +27.213.109.105 27.213.175.208 27.213.255.202 27.213.66.112 @@ -1674,9 +1578,9 @@ 27.215.190.172 27.215.212.209 27.215.253.149 -27.215.34.242 27.215.71.243 27.215.98.242 +27.216.117.54 27.216.128.156 27.216.131.66 27.216.144.66 @@ -1698,17 +1602,13 @@ 27.220.85.168 27.221.239.223 27.222.241.223 -27.222.249.210 27.222.76.80 27.223.242.164 27.24.28.134 27.35.129.198 27.35.154.13 -27.35.16.145 -27.35.2.30 27.35.212.124 27.35.58.5 -27.41.237.129 27.43.117.98 31.0.98.131 31.11.51.57 @@ -1735,18 +1635,19 @@ 32.208.157.193 32792.prolocksmithwinterpark.com 35.184.169.169 -36.107.209.10 36.108.231.218 36.248.228.64 +36.248.83.98 36.250.203.246 36.251.157.225 36.251.18.18 36.251.51.244 36.255.90.219 +36.33.128.58 36.33.160.167 36.34.150.236 36.66.105.159 -36.66.111.203 +36.66.133.125 36.66.139.36 36.89.18.133 360.lcy2zzx.pw @@ -1816,7 +1717,6 @@ 39.81.70.88 39.83.94.11 39.84.115.152 -39.85.54.191 39.85.54.4 39.86.129.233 39.86.170.209 @@ -1827,10 +1727,10 @@ 39.88.155.96 39.88.233.131 39.88.67.238 +39.88.72.9 39.89.108.109 39.89.145.11 39.89.146.198 -39.89.146.36 39.89.63.23 39.90.86.212 40.88.2.151 @@ -1841,14 +1741,15 @@ 41.219.185.171 41.226.60.115 41.72.203.82 -41.86.18.169 -41.86.21.23 +41.86.18.133 41.86.21.27 -41.86.21.38 +41.86.5.197 42.202.101.199 +42.228.39.211 42.228.43.161 42.228.65.104 42.230.82.176 +42.232.81.179 42.235.180.147 42.239.26.122 42.56.15.227 @@ -1862,7 +1763,9 @@ 45.133.1.242 45.133.203.192 45.135.134.228 +45.14.149.182 45.14.149.204 +45.141.84.182 45.141.84.184 45.144.225.118 45.144.225.135 @@ -1888,16 +1791,12 @@ 45.51.104.59 45.6.24.251 45.81.235.31 -45.85.90.131 -45.85.90.179 45.85.90.203 45.9.148.37 45.92.108.125 -45.95.169.153 46.117.42.29 46.172.75.231 46.182.173.246 -46.182.173.247 46.20.63.218 46.214.27.4 46.24.130.254 @@ -1915,6 +1814,7 @@ 47.16.131.51 47.21.202.98 47.46.231.38 +49.119.187.230 49.142.162.113 49.142.87.36 49.143.43.93 @@ -1929,7 +1829,6 @@ 49.68.221.252 5.188.62.111 5.2.70.50 -5.42.37.74 5.53.146.179 5.79.75.210 5.95.226.154 @@ -1937,7 +1836,6 @@ 50.115.174.106 50.121.91.255 50.252.47.29 -51.222.56.159 54.36.114.136 54.36.180.122 58.114.246.26 @@ -1952,16 +1850,15 @@ 58.218.67.253 58.22.212.107 58.226.129.29 -58.229.194.122 58.230.89.42 58.238.42.192 58.240.147.97 58.241.78.55 -58.243.123.212 58.243.126.133 58.243.208.225 -58.248.118.64 -58.249.80.181 +58.248.142.227 +58.249.79.174 +58.249.84.131 58.48.154.143 58.72.165.153 58.72.165.39 @@ -1970,12 +1867,14 @@ 59.0.211.161 59.102.168.189 59.151.202.3 -59.151.207.150 59.151.214.4 59.151.237.51 59.151.246.125 59.23.114.97 59.58.117.226 +59.93.18.144 +59.96.37.124 +59.97.169.237 60.10.91.242 60.13.61.12 60.164.130.220 @@ -2000,9 +1899,7 @@ 60.217.177.196 60.217.86.208 60.223.84.102 -60.25.109.240 60.253.15.104 -60.253.39.88 60.253.4.72 60.253.51.127 60.253.60.174 @@ -2012,25 +1909,21 @@ 60.7.8.43 60.7.99.254 61.164.96.98 -61.179.171.60 61.179.91.194 61.247.224.66 61.253.94.230 -61.3.149.112 61.41.230.161 61.47.220.169 61.52.103.217 61.52.199.47 -61.52.207.10 61.52.30.172 61.52.9.166 -61.52.9.62 61.52.99.161 -61.53.102.137 61.53.117.237 -61.53.220.0 +61.53.89.220 61.54.103.56 61.54.64.63 +61.54.69.77 61.56.180.67 61.56.181.7 61.57.96.116 @@ -2131,7 +2024,6 @@ 74.64.139.223 74.75.165.81 75.127.141.52 -75.82.36.220 75.83.102.27 75.99.213.61 76.170.11.82 @@ -2143,7 +2035,6 @@ 76.95.12.137 77.111.182.31 77.237.25.210 -77.53.144.46 77.71.50.153 77.71.52.220 77.89.203.238 @@ -2165,6 +2056,7 @@ 79.130.253.13 79.147.123.48 79.175.42.244 +79.21.84.63 79.7.170.58 79.79.58.94 79.8.70.162 @@ -2178,6 +2070,7 @@ 81.165.44.109 81.191.40.58 81.213.141.184 +81.215.199.29 81.218.187.113 81.218.195.216 81.237.128.200 @@ -2245,7 +2138,7 @@ 86.35.43.220 87.172.19.130 87.61.89.40 -87du.vip +88.119.171.253 88.2.208.71 88.2.219.179 88.225.222.128 @@ -2279,6 +2172,7 @@ 92.114.191.82 92.241.78.114 92.27.246.202 +92.54.237.237 92.83.62.139 92.85.18.138 93.159.169.190 @@ -2306,7 +2200,6 @@ 95.60.146.134 95.66.196.63 95.9.120.40 -95.9.81.85 96.239.73.246 96.47.147.169 97.68.140.254 @@ -2378,6 +2271,7 @@ anadelgbt.org anantam.net.in andreelapeyre.com andremaraisbeleggings.co.za +andreonemaia.com andres.ac.ug andres.ug andreshconcejal.solucioneslink.com @@ -2387,7 +2281,6 @@ angloteste.bigprime.com.br anhung1102.vn anurontv.com anysbergbiltong.co.za -apartamentoscitta.com api-ms.cobainaja.id api.cstdevs.com api.quocbao.biz @@ -2410,15 +2303,17 @@ atlasconcreteworks.com attach.66rpg.com atteuqpotentialunlimited.com augustair.com +aulist.com +automaticrefreshments.com avadhanagames.com ayahuascasp.com.br ayamallah.com +aycconsultoriaempresarial.com azmeasurement.com b2b.toptanakaryakit.com.tr backgrounds.pk badeggdesign.com balealgodon.mx -ballina.andrewmaughan.com bangkok-orchids.com bangladeshunbound.com bary.sz4h.com @@ -2429,6 +2324,7 @@ bbia.co.uk bcmt.elin.co.za bcrg.co.za bdnextrend.xyz +beanx88.xyz bearcatpumps.com.cn beautincollagen.rs bekape.co.id @@ -2436,6 +2332,7 @@ beor360.com bespokeweddings.ie bestcarenepal.com betone.co.kr +betycopaints.com beveragesmiami.solucioneslink.com bhavaniengineering.com bigmikesupplies.co.za @@ -2464,6 +2361,7 @@ bophelocare.co.za bounces.mi-fs.com boutiqueofferte.com bpo.correct.go.th +bradleyinstitute.co.za brandtrust.com.pk braunfinancial.com.au brendanquine.com @@ -2514,6 +2412,7 @@ chezalice.co.za childselect.com chinhdropfile.myvnc.com chinhdropfile80.myvnc.com +chipmania.it cible-energy.com cifeer.net cirugiadenarizbucaramanga.com @@ -2527,10 +2426,9 @@ cloud.fc.co.mz cm-arquitetos.com codsambal.com colempaques.info -colinde.pricesne.com colorpak.pl +columbia.aula-web.net community.reimclub.com -comosairdoburaco.com.br competancy.indigoconsult.net conceptimagine.ro config.cqhbkjzx.com @@ -2546,7 +2444,6 @@ covid19.cyberschool.or.id cpanel.shivay.net cr-sq.com craftech.nxtnet.ga -crearechile.cl creationskateboards.com crecerco.com crittersbythebay.com @@ -2556,7 +2453,6 @@ crmroche.manivelasst.com crscorretordeimoveis.com.br cse-engineer.com csnserver.com -ctracknxt.in cubescargoexpress.com curasoles.co.za currantmedia.com @@ -2575,7 +2471,6 @@ data.cdevelop.org data.over-blog-kiwi.com datapolish.com dating.khokhas.co.za -datsom.vn davethompson.me.uk davidmcguinness.info dayspringdaisies.com @@ -2599,7 +2494,6 @@ destinymc.co.za detorre.es dev.sebpo.net dev.watch-store.eu -dezcom.com dfcf.91756.cn dfsfcsfcdsfsdvcfsvcscv.com diamantenegro.mi-fs.com @@ -2614,6 +2508,7 @@ dl.installcdn-aws.com dl.packetstormsecurity.net dl.rina-roleplay.com dnn.alibuf.com +dns.alibuf.com dns.cyberium.cc dockerupdate.anondns.net docman.orientalservices.in @@ -2630,6 +2525,8 @@ dosame.com dosman.pl dovberger.com down.pcclear.com +down.postch-de.top +down.postch-dl.top down.udashi.com down.webbora.com down1.arpun.com @@ -2689,14 +2586,13 @@ extrovertoffers.com f1sol.com fahrzeugdrive.com familydentist.site -faveraprojects.com fc.co.mz felicienne.nl files.martellexpress.us filmotainment.com final.makkahkmcc.com fineartgallerym.com -fisconline.casa +fisconline.bar fix-america-now.org fixauto.illumetechnology.com fixturegovernment.com @@ -2711,7 +2607,6 @@ foothills.com.br footweardirect.elin.co.za forum.mdb.nu fotoobjetivo.com -foundationrepairhoustontx.net foxeps.com.br fraud.bpcbankingtech.com freecnetdownload.com @@ -2720,7 +2615,6 @@ ftp.n3twork30cm.ml fullelectronica.com.ar funletters.net fusionfiresolutions.com -futbolpr.com futuregraphics.com.ar g.pinmonkey.xyz gametwogame.com @@ -2737,6 +2631,7 @@ ghettohub.co.za ghislain.dartois.pagesperso-orange.fr giadungg7.com giddos.ga +giteletropical.com glowinmedia.co.ke gmsebpl.com gmtransformationacademy.com @@ -2749,6 +2644,7 @@ goldcoastoffice365.com goldcoastoffice365.com.au golden-memories-funerals.yourpageserver.com goldenasiacapital.com +goldmen.in gorecycle.fahadjutt.com gpotecnosystems.com gracejukes.com @@ -2777,13 +2673,12 @@ hhaward.org highlandroadcoc.com highlandslasvegas.atakdev.com hindi.factsriver.com -hiptool.net hitpe.com hitstation.nl +hlmd.in hmpmall.co.kr hoagietesting10.com hoayeuthuong-my.sharepoint.com -holmesservices.mobiledevsite.co homefindersolutions.com hongluosi.com hookedupboatclub.com @@ -2794,7 +2689,6 @@ houstonshutters.site hr2019.vrcom7.com hrnautica.com.br hseda.com -hsmwebapp.com htownbars.com hubtech.co.za huellacero.cl @@ -2834,16 +2728,19 @@ ioabc.wif.com.br ipmes.ma iremart.es iris101.co.uk +isaac.mikhailmotoringschool.com iscamenabe.com isiphephelocon.co.za iso-dubai.net israrulhaq.me +isrorg.com isso.ps ist-security.com it123.ru italiandirezione.casa itc-demo.softgig.co.ke itelsys.ma +itmotasaciones.com jacktech.jackindia.com jaishritours.com jamiekaylive.com @@ -2857,6 +2754,7 @@ jennwolfemtb.com jhayesconsulting.com jiaoyuzixun.cn jing-da.com.tw +jmtc.91756.cn jnanbharati.com jobs.thebeessolution.com joelbonissilver.com @@ -2867,6 +2765,7 @@ jumpmanualjacobhiller.com jupiter.toxsl.in justinscott.com.au kadigital.co.uk +kaizenjanitorial.com kalawatihomes.com kalogirosfinance.com kaptaanchapal.com @@ -2928,14 +2827,16 @@ lotusanddragonfly.com lp.definerisco.com lp.difusodesign.com lp.quama.pe -ltc.typoten.com +luckybrownie.com luminouspneuma.com luxomodels.com m-technics.kz m.estudiomoros.com.ar m.mobilelocalsales.com +m.softsharks.com madicon.co.za magianegramagiablancayamarres.com +maharaniworld.com mail.bs-eiendomme.co.za mail.golimoapp.com mail.jeffsono.org @@ -2961,7 +2862,6 @@ matruchhaya.co.in maxiquim.cl maxoprint.co.uk maxtox.com.pk -maybethescobar.com mbgrm.com mbjtimes.com mbsolutions.ge @@ -2992,11 +2892,12 @@ michaelphilip.com michimal2.000webhostapp.com microblading.mirliandias.com.br microcomm-group.com +mikhailmotoringschool.com +mills-skyla30ec.com mingguanwms.com minuevavida.org mirror.mypage.sk misterson.com -mixr.at mkontakt.az mktf.mx mmdx.com @@ -3033,6 +2934,7 @@ navayurveda.in nec-i.com nedkellymyanmar.com nelitrianggraeni.000webhostapp.com +nellaimasthanbiryani.com nerve.untergrund.net nettube.com.br networkwheels.co.za @@ -3057,7 +2959,6 @@ njtiledesigncenter.com nobius.org nocalnoodle.elin.co.za nomadicbees.com -nonnarina.ax notamuzikaletleri.com ns1.the-widyantos.com nsb.org.uk @@ -3077,12 +2978,15 @@ omaromatic.com omega.az oms.pappai.com omscoc.pappai.com +onedigitalcard.granvizionnecorp.com onedrive.listifyapp.co online.creedglobal.in onlinestatis.bar +open.rawntech.com open.warehousesaas.co.uk opentoronto.org opolis.io +opticaoptigral.cl optimus.com.sg order.bizpeed.com orientgatewayltd.com @@ -3120,6 +3024,7 @@ pcsoori.com pd.oceaniarp.net pemdodo.com perfumeriamontes.es +periodiche.bar perpus.onlineman7-jombang.sch.id perpustekim.untirta.ac.id pestoclean.co.uk @@ -3139,6 +3044,7 @@ pmglance.startwriteup.com pointactionsg.com pokojewewladyslawowie.pl pole.com.vc +ponchokhana.com pool.phxdir.com pooltablemoversdenver.net portal.premiumpunch.com @@ -3149,6 +3055,7 @@ prestasicash.com.ar prestigehomeautomation.net preview2.behalen.com prishaartcreations.com +prismaxis.com production.sparshims.com programaoperadoronline.com.br project.exquitec.com @@ -3200,7 +3107,6 @@ reseller.itechbrasil.com resuco.net rezkabum.ru rhema.com.sg -richancyber.info richmondminerals.co.zm rinaefoundation.org.za rinkaisystem-ht.com @@ -3209,7 +3115,6 @@ rkcable.co.in rkverify.securestudies.com robertmcardle.com robertsinclair.net -romanianpoints.com ronnietucker.co.uk roomsvc.servegate.kr roshnijewellery.com @@ -3219,7 +3124,6 @@ rubycityvietnam.com ruisgood.ru ruwadalkuwait.com rydchile.cl -s.51shijuan.com s.thechinesemuslim.com sac2.11xii.com sacredscentsonline.com @@ -3253,7 +3157,9 @@ serendibsourcing.com sericaasia.com servicemhkd.myvnc.com servicemhkd80.myvnc.com +serviciovirtual.com.ar sexologistpakistan.net +seyranikenger.com.tr sgb.ac.ke sgessy.com.br shaheentbfoundation.com @@ -3304,6 +3210,7 @@ spaceframe.mobi.space-frame.co.za special-key.cf spent.com.pl spetsesyachtcharter.gr +spiritualroot.org spititourism.com spittinfire.com sports-net.de @@ -3323,7 +3230,7 @@ stiepancasetia.ac.id stlukesohag.com store.ericalgarin.com stott-thompson.co.uk -streetdemo.yourpageserver.com +stratexec.co.za suboldesign.com sumerians.org sunaryem.com.tr @@ -3371,6 +3278,7 @@ test.lubrico.in test.typoten.com test.wanepghana.org test1.asistencia247.com +test1.milenial.id test1.tenplusone.my test2.basis-web.com test2.marrenconstruction.ie @@ -3395,7 +3303,7 @@ themansionkasauli.com theprofinn.com thesummitpc.net theurbantutors.com -thientu.net +thirdstringcalifornia.com thosewebbs.com thriveink.com tianangdep.com @@ -3405,7 +3313,6 @@ timamollo.co.za timegonebuy.com tksb.net tlcc.com.gt -tntmedia.gr todoapp.cstdevs.com todocontodo.com.mx tonydong.com @@ -3442,6 +3349,7 @@ ultimate-24.de umwelt-kirchhof.de unicorpbrunei.com uniengrisb.com +unisoftcc.com unyazitelecom.com upcbpta.com urbantrapfest.cl @@ -3456,7 +3364,9 @@ vbcargo.hu vcah.co.uk vectarts.com vegadelcasero.cl +velma-harber30ku.com vendas.lidiacarmeli.com.br +versualstudio.com veterinariadrpopui.com vfocus.net vienen.gblix.srv.br @@ -3483,6 +3393,7 @@ vvsskmodinationalschool.com w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu wanepliberia.org wanepniger.org +weareactum.com web.eng.ubu.ac.th web.geetle.ga web.geomegasoft.net @@ -3510,6 +3421,7 @@ wolfgang-brodte.de wonderhawaii.com woodsytech.com wordpress.saleensuporte.com.br +workingsolutionsrome.org wozata.000webhostapp.com wp.readhere.in wpdemo.101clients.com.au @@ -3531,7 +3443,6 @@ yoast.yourpageserver.com yourclub1.com yourtopdog.com.au youtubetrainingacademy.com -yp.hnggzyjy.cn yskadvisors.com yummyyogaudaipur.com yzkzixun.com @@ -3584,7 +3495,6 @@ zz.690tx.com ||bitbucket.org/tanake5518/fi/downloads/clientrevers.txt$all ||bitbucket.org/tanake5518/fi/downloads/dcrat.exe$all ||bitbucket.org/tanake5518/fi/downloads/dllservices.exe$all -||bitbucket.org/tanake5518/fi/downloads/dllservices2.exe$all ||bitbucket.org/tanake5518/fi/downloads/exe_morris.mcdermott.exe$all ||bitbucket.org/tanake5518/fi/downloads/hans.txt$all ||bitbucket.org/tanake5518/fi/downloads/hulu.txt$all @@ -3615,7 +3525,6 @@ zz.690tx.com ||bitbucket.org/tanake5518/fi/downloads/taurjok.txt$all ||bitbucket.org/tanake5518/fi/downloads/taurusbabac.exe$all ||bitbucket.org/tanake5518/fi/downloads/telekiller.exe$all -||bitbucket.org/tanake5518/fi/downloads/updateanddr.txt$all ||bitbucket.org/tanake5518/fi/downloads/updateandr.txt$all ||bitbucket.org/tanake5518/fi/downloads/vhajeja.txt$all ||bitbucket.org/tanake5518/fi/downloads/word.txt$all @@ -3654,7 +3563,6 @@ zz.690tx.com ||drive.google.com/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv$all ||drive.google.com/uc?export=download&id=1cos43rmscrescxk3u40qjuqbwr-pydsn$all ||drive.google.com/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben$all -||drive.google.com/uc?export=download&id=1dhoxtwbb2ycn8q06gi3p-ao_llldff0e$all ||drive.google.com/uc?export=download&id=1dnm3wtjf6ud5fv6zop9cvbr4rs2of1-n$all ||drive.google.com/uc?export=download&id=1dqin1sdd6rbah3sggzsxzeqgrkmhjnqm$all ||drive.google.com/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi$all @@ -3708,6 +3616,7 @@ zz.690tx.com ||files.constantcontact.com/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls$all ||files.constantcontact.com/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx$all ||gist.githubusercontent.com/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe$all +||hostingcloud.racing/7991.js$all ||hqdecig.com/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/$all ||hsecaravans.co.uk/wp-admin/suy/$all ||ia801802.us.archive.org/19/items/startup_20210219/startup.txt$all @@ -3723,7 +3632,10 @@ zz.690tx.com ||ksh.hu/docs/adatgyujtesek/elektra/csv_to_xml.exe$all ||kuaizip.com/down/affiliate/kuaizip_setup_10029.exe$all ||linuxforensicsbook.com.s3.amazonaws.com/linuxforensicscode.zip$all +||marcostrombetta.com.br/ds/1802.gif$all ||minpic.de/k/big5/1giof6/$all +||morrobaydrugandgift.com/wp-contentbak/t9m/$all +||moumitas.com/ds/0204.gif$all ||my.cloudme.com/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe$all ||nch.com.au/components/aacenc.exe$all ||nch.com.au/components/doxillionsetup.exe$all @@ -3755,8 +3667,6 @@ zz.690tx.com ||onedrive.live.com/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq$all ||onedrive.live.com/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko$all ||onedrive.live.com/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw$all -||onedrive.live.com/download?cid=032ce380af7ab389&resid=32ce380af7ab389!210&authkey=akcynbtc0h3ui7e$all -||onedrive.live.com/download?cid=032ce380af7ab389&resid=32ce380af7ab389%21210&authkey=akcynbtc0h3ui7e$all ||onedrive.live.com/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma$all ||onedrive.live.com/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48$all ||onedrive.live.com/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq$all @@ -3791,12 +3701,15 @@ zz.690tx.com ||onedrive.live.com/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4$all ||onedrive.live.com/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve$all ||onedrive.live.com/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w$all +||onedrive.live.com/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a$all ||onedrive.live.com/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a$all ||onedrive.live.com/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg$all ||onedrive.live.com/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60$all ||onedrive.live.com/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg$all ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4$all ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c$all +||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0$all +||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!140&authkey=apn44x6bxlzq3ac$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!151&authkey=aeuk7knodrpenek$all @@ -3806,30 +3719,20 @@ zz.690tx.com ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd$all -||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21140&authkey=apn44x6bxlzq3ac$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21151&authkey=aeuk7knodrpenek$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21153&authkey=ao6e8g0bzbp_idw$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21154&authkey=ah4chedbotzpmtq$all ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21156&authkey=ajnqscnmrdonpkg$all -||onedrive.live.com/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po$all ||onedrive.live.com/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe$all ||onedrive.live.com/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk$all ||onedrive.live.com/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca$all -||onedrive.live.com/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca$all ||onedrive.live.com/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu$all ||onedrive.live.com/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k$all ||onedrive.live.com/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo$all -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk$all -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei$all -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte$all -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk$all -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei$all -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte$all ||onedrive.live.com/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga$all ||onedrive.live.com/download?cid=2968c371f5450503&resid=2968c371f5450503!122&authkey=aaqhhxbnwfwrz28$all -||onedrive.live.com/download?cid=2968c371f5450503&resid=2968c371f5450503%21122&authkey=aaqhhxbnwfwrz28$all ||onedrive.live.com/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0$all ||onedrive.live.com/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620$all ||onedrive.live.com/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo$all @@ -3854,7 +3757,6 @@ zz.690tx.com ||onedrive.live.com/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8$all ||onedrive.live.com/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc$all ||onedrive.live.com/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0$all -||onedrive.live.com/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8$all ||onedrive.live.com/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus$all ||onedrive.live.com/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa$all ||onedrive.live.com/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa$all @@ -3873,7 +3775,6 @@ zz.690tx.com ||onedrive.live.com/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog$all ||onedrive.live.com/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog$all ||onedrive.live.com/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky$all -||onedrive.live.com/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky$all ||onedrive.live.com/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba!2203&authkey=ajvalmr5l8epwvm$all ||onedrive.live.com/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba%212203&authkey=ajvalmr5l8epwvm$all ||onedrive.live.com/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm$all @@ -3899,7 +3800,6 @@ zz.690tx.com ||onedrive.live.com/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc$all ||onedrive.live.com/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8$all -||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts$all @@ -3909,9 +3809,11 @@ zz.690tx.com ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas$all +||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i$all +||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c$all ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy$all @@ -3938,9 +3840,11 @@ zz.690tx.com ||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so$all ||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq$all ||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s$all +||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww$all ||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8$all ||onedrive.live.com/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4$all ||onedrive.live.com/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu$all +||onedrive.live.com/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi$all ||onedrive.live.com/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8$all ||onedrive.live.com/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8$all ||onedrive.live.com/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2$all @@ -3949,6 +3853,7 @@ zz.690tx.com ||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8$all ||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq$all ||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8$all +||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq$all ||onedrive.live.com/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g$all ||onedrive.live.com/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum$all ||onedrive.live.com/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi$all @@ -3963,11 +3868,11 @@ zz.690tx.com ||onedrive.live.com/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki$all ||onedrive.live.com/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s$all ||onedrive.live.com/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki$all -||onedrive.live.com/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s$all ||onedrive.live.com/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc$all ||onedrive.live.com/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc$all ||onedrive.live.com/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo$all ||onedrive.live.com/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva$all +||onedrive.live.com/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc$all ||onedrive.live.com/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles$all ||onedrive.live.com/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg$all ||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai$all @@ -3991,11 +3896,9 @@ zz.690tx.com ||onedrive.live.com/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21109&authkey=ap-okubj9bvtlc0$all ||onedrive.live.com/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi$all ||onedrive.live.com/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e$all -||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90$all ||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c$all ||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90$all ||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c$all -||onedrive.live.com/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk$all ||onedrive.live.com/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4$all ||onedrive.live.com/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo$all ||onedrive.live.com/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2!517&authkey=akfewcyiwlwomyk$all @@ -4026,7 +3929,6 @@ zz.690tx.com ||onedrive.live.com/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21305&authkey=an-uuhplpk2zp5u$all ||onedrive.live.com/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu$all ||onedrive.live.com/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i$all -||onedrive.live.com/download?cid=70d8fa75c83fbdbe&resid=70d8fa75c83fbdbe%21144&authkey=acw8wl1noncfp-4$all ||onedrive.live.com/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam$all ||onedrive.live.com/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble$all ||onedrive.live.com/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60$all @@ -4049,6 +3951,7 @@ zz.690tx.com ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum$all ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto$all ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum$all +||onedrive.live.com/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm$all ||onedrive.live.com/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125570&authkey=aejqgjglwurnb0a$all ||onedrive.live.com/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq$all ||onedrive.live.com/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k$all @@ -4059,9 +3962,6 @@ zz.690tx.com ||onedrive.live.com/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny$all ||onedrive.live.com/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s$all ||onedrive.live.com/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs$all -||onedrive.live.com/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli$all -||onedrive.live.com/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18$all -||onedrive.live.com/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli$all ||onedrive.live.com/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm$all ||onedrive.live.com/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8$all ||onedrive.live.com/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm$all @@ -4087,8 +3987,8 @@ zz.690tx.com ||onedrive.live.com/download?cid=907247dc330a3f33&resid=907247dc330a3f33!254&authkey=ajt5wxegbvzbwqa$all ||onedrive.live.com/download?cid=907247dc330a3f33&resid=907247dc330a3f33!255&authkey=aaimhpp89qmcfhc$all ||onedrive.live.com/download?cid=907247dc330a3f33&resid=907247dc330a3f33%21254&authkey=ajt5wxegbvzbwqa$all -||onedrive.live.com/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s$all ||onedrive.live.com/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my$all +||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc$all ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby$all ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo$all ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti$all @@ -4096,27 +3996,11 @@ zz.690tx.com ||onedrive.live.com/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8$all ||onedrive.live.com/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o$all ||onedrive.live.com/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!305&authkey=apgh_teb3673nek$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!306&authkey=aibymhcuhqnmrwo$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm$all -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21305&authkey=apgh_teb3673nek$all ||onedrive.live.com/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m$all ||onedrive.live.com/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w$all ||onedrive.live.com/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk$all ||onedrive.live.com/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk$all ||onedrive.live.com/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k$all -||onedrive.live.com/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli$all ||onedrive.live.com/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm$all ||onedrive.live.com/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue$all ||onedrive.live.com/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma$all @@ -4135,7 +4019,6 @@ zz.690tx.com ||onedrive.live.com/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8$all ||onedrive.live.com/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq$all ||onedrive.live.com/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq$all -||onedrive.live.com/download?cid=9fb622acb27482ef&resid=9fb622acb27482ef%211197&authkey=aeacibxy2zlyxro$all ||onedrive.live.com/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o$all ||onedrive.live.com/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4$all ||onedrive.live.com/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi$all @@ -4148,7 +4031,6 @@ zz.690tx.com ||onedrive.live.com/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs$all ||onedrive.live.com/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw$all ||onedrive.live.com/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o$all -||onedrive.live.com/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc$all ||onedrive.live.com/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs$all ||onedrive.live.com/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw$all ||onedrive.live.com/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu$all @@ -4226,9 +4108,6 @@ zz.690tx.com ||onedrive.live.com/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs$all ||onedrive.live.com/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m$all ||onedrive.live.com/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga$all -||onedrive.live.com/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk$all -||onedrive.live.com/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!362&authkey=alycl9izrvfl7oc$all -||onedrive.live.com/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21362&authkey=alycl9izrvfl7oc$all ||onedrive.live.com/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg$all ||onedrive.live.com/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a$all ||onedrive.live.com/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a$all @@ -4282,6 +4161,7 @@ zz.690tx.com ||onedrive.live.com/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu$all ||onedrive.live.com/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu$all ||onedrive.live.com/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq$all +||onedrive.live.com/download?cid=e627fc797baa3032&resid=e627fc797baa3032!2324&authkey=aa8i-r7ixmcraha$all ||onedrive.live.com/download?cid=e627fc797baa3032&resid=e627fc797baa3032%212324&authkey=aa8i-r7ixmcraha$all ||onedrive.live.com/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke$all ||onedrive.live.com/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom$all @@ -4296,7 +4176,6 @@ zz.690tx.com ||onedrive.live.com/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw$all ||onedrive.live.com/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw$all ||onedrive.live.com/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai$all -||onedrive.live.com/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc$all ||onedrive.live.com/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8$all ||onedrive.live.com/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns$all ||onedrive.live.com/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8$all @@ -4306,7 +4185,6 @@ zz.690tx.com ||onedrive.live.com/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa$all ||onedrive.live.com/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4$all ||onedrive.live.com/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8$all -||onedrive.live.com/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa$all ||onedrive.live.com/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0$all ||onedrive.live.com/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw$all ||onedrive.live.com/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e$all @@ -4315,7 +4193,6 @@ zz.690tx.com ||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k$all ||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie$all ||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c$all -||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g$all ||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta$all ||onedrive.live.com/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o$all ||onedrive.live.com/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao$all @@ -4335,6 +4212,7 @@ zz.690tx.com ||onedrive.live.com/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0$all ||onedrive.live.com/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc$all ||onedrive.live.com/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu$all +||onedrive.live.com/download?cid=fd67fafc46d3c687&resid=fd67fafc46d3c687%21473&authkey=aoid_cp-jgffqvm$all ||onedrive.live.com/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm$all ||onedrive.live.com/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w$all ||onedrive.live.com/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm$all @@ -4353,7 +4231,6 @@ zz.690tx.com ||onedrive.live.com/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm$all ||onedrive.live.com/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta$all ||paste.ee/r/a39ev$all -||paste.ee/r/oitkz$all ||pastebin.com/raw/77jhk0iw$all ||pastebin.com/raw/89hkc7wb$all ||pastebin.com/raw/yqvsvlvq$all @@ -4385,10 +4262,10 @@ zz.690tx.com ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt$all ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt$all ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt$all +||storage.googleapis.com/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt$all ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt$all ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt$all ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg$all -||storage.googleapis.com/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt$all ||storage.googleapis.com/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt$all ||technologydistilled.com/a-nurse-ss8d9/z/$all ||tsrv4.ws/23.exe$all @@ -4403,3 +4280,4 @@ zz.690tx.com ||websound.ru/issues/146_150/bc_memories_from_the_mcp.exe$all ||websound.ru/issues/151_155/tidex_-_short_stuff.exe$all ||wikileaks.org/syria-files/attach/222/222051_instruction.zip$all +||yp.hnggzyjy.cn/common/yz.vbs$all diff --git a/urlhaus-filter-rpz-online.conf b/urlhaus-filter-rpz-online.conf index a70f562a..1202ca46 100644 --- a/urlhaus-filter-rpz-online.conf +++ b/urlhaus-filter-rpz-online.conf @@ -1,12 +1,12 @@ ; Title: Online Malicious Domains RPZ Blocklist -; Updated: Sat, 03 Apr 2021 00:13:46 UTC +; Updated: Sat, 03 Apr 2021 12:12:28 UTC ; Expires: 1 day (update frequency) ; Homepage: https://gitlab.com/curben/urlhaus-filter ; License: https://gitlab.com/curben/urlhaus-filter#license ; Source: https://urlhaus.abuse.ch/api/ $TTL 30 -@ IN SOA rpz.curben.gitlab.io. hostmaster.rpz.curben.gitlab.io. 1617408838 86400 3600 604800 30 +@ IN SOA rpz.curben.gitlab.io. hostmaster.rpz.curben.gitlab.io. 1617451959 86400 3600 604800 30 NS localhost. 0-24bpautomentes.hu CNAME . @@ -21,7 +21,6 @@ $TTL 30 360down7.miiyun.cn CNAME . 77st.net CNAME . 8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com CNAME . -87du.vip CNAME . 8poieq.bn.files.1drv.com CNAME . aatreefelling.co.za CNAME . abad.tv CNAME . @@ -82,6 +81,7 @@ anadelgbt.org CNAME . anantam.net.in CNAME . andreelapeyre.com CNAME . andremaraisbeleggings.co.za CNAME . +andreonemaia.com CNAME . andres.ac.ug CNAME . andres.ug CNAME . andreshconcejal.solucioneslink.com CNAME . @@ -91,7 +91,6 @@ angloteste.bigprime.com.br CNAME . anhung1102.vn CNAME . anurontv.com CNAME . anysbergbiltong.co.za CNAME . -apartamentoscitta.com CNAME . api-ms.cobainaja.id CNAME . api.cstdevs.com CNAME . api.quocbao.biz CNAME . @@ -114,15 +113,17 @@ atlasconcreteworks.com CNAME . attach.66rpg.com CNAME . atteuqpotentialunlimited.com CNAME . augustair.com CNAME . +aulist.com CNAME . +automaticrefreshments.com CNAME . avadhanagames.com CNAME . ayahuascasp.com.br CNAME . ayamallah.com CNAME . +aycconsultoriaempresarial.com CNAME . azmeasurement.com CNAME . b2b.toptanakaryakit.com.tr CNAME . backgrounds.pk CNAME . badeggdesign.com CNAME . balealgodon.mx CNAME . -ballina.andrewmaughan.com CNAME . bangkok-orchids.com CNAME . bangladeshunbound.com CNAME . bary.sz4h.com CNAME . @@ -133,6 +134,7 @@ bbia.co.uk CNAME . bcmt.elin.co.za CNAME . bcrg.co.za CNAME . bdnextrend.xyz CNAME . +beanx88.xyz CNAME . bearcatpumps.com.cn CNAME . beautincollagen.rs CNAME . bekape.co.id CNAME . @@ -140,6 +142,7 @@ beor360.com CNAME . bespokeweddings.ie CNAME . bestcarenepal.com CNAME . betone.co.kr CNAME . +betycopaints.com CNAME . beveragesmiami.solucioneslink.com CNAME . bhavaniengineering.com CNAME . bigmikesupplies.co.za CNAME . @@ -168,6 +171,7 @@ bophelocare.co.za CNAME . bounces.mi-fs.com CNAME . boutiqueofferte.com CNAME . bpo.correct.go.th CNAME . +bradleyinstitute.co.za CNAME . brandtrust.com.pk CNAME . braunfinancial.com.au CNAME . brendanquine.com CNAME . @@ -218,6 +222,7 @@ chezalice.co.za CNAME . childselect.com CNAME . chinhdropfile.myvnc.com CNAME . chinhdropfile80.myvnc.com CNAME . +chipmania.it CNAME . cible-energy.com CNAME . cifeer.net CNAME . cirugiadenarizbucaramanga.com CNAME . @@ -231,10 +236,9 @@ cloud.fc.co.mz CNAME . cm-arquitetos.com CNAME . codsambal.com CNAME . colempaques.info CNAME . -colinde.pricesne.com CNAME . colorpak.pl CNAME . +columbia.aula-web.net CNAME . community.reimclub.com CNAME . -comosairdoburaco.com.br CNAME . competancy.indigoconsult.net CNAME . conceptimagine.ro CNAME . config.cqhbkjzx.com CNAME . @@ -250,7 +254,6 @@ covid19.cyberschool.or.id CNAME . cpanel.shivay.net CNAME . cr-sq.com CNAME . craftech.nxtnet.ga CNAME . -crearechile.cl CNAME . creationskateboards.com CNAME . crecerco.com CNAME . crittersbythebay.com CNAME . @@ -260,7 +263,6 @@ crmroche.manivelasst.com CNAME . crscorretordeimoveis.com.br CNAME . cse-engineer.com CNAME . csnserver.com CNAME . -ctracknxt.in CNAME . cubescargoexpress.com CNAME . curasoles.co.za CNAME . currantmedia.com CNAME . @@ -279,7 +281,6 @@ data.cdevelop.org CNAME . data.over-blog-kiwi.com CNAME . datapolish.com CNAME . dating.khokhas.co.za CNAME . -datsom.vn CNAME . davethompson.me.uk CNAME . davidmcguinness.info CNAME . dayspringdaisies.com CNAME . @@ -303,7 +304,6 @@ destinymc.co.za CNAME . detorre.es CNAME . dev.sebpo.net CNAME . dev.watch-store.eu CNAME . -dezcom.com CNAME . dfcf.91756.cn CNAME . dfsfcsfcdsfsdvcfsvcscv.com CNAME . diamantenegro.mi-fs.com CNAME . @@ -318,6 +318,7 @@ dl.installcdn-aws.com CNAME . dl.packetstormsecurity.net CNAME . dl.rina-roleplay.com CNAME . dnn.alibuf.com CNAME . +dns.alibuf.com CNAME . dns.cyberium.cc CNAME . dockerupdate.anondns.net CNAME . docman.orientalservices.in CNAME . @@ -334,6 +335,8 @@ dosame.com CNAME . dosman.pl CNAME . dovberger.com CNAME . down.pcclear.com CNAME . +down.postch-de.top CNAME . +down.postch-dl.top CNAME . down.udashi.com CNAME . down.webbora.com CNAME . down1.arpun.com CNAME . @@ -393,14 +396,13 @@ extrovertoffers.com CNAME . f1sol.com CNAME . fahrzeugdrive.com CNAME . familydentist.site CNAME . -faveraprojects.com CNAME . fc.co.mz CNAME . felicienne.nl CNAME . files.martellexpress.us CNAME . filmotainment.com CNAME . final.makkahkmcc.com CNAME . fineartgallerym.com CNAME . -fisconline.casa CNAME . +fisconline.bar CNAME . fix-america-now.org CNAME . fixauto.illumetechnology.com CNAME . fixturegovernment.com CNAME . @@ -415,7 +417,6 @@ foothills.com.br CNAME . footweardirect.elin.co.za CNAME . forum.mdb.nu CNAME . fotoobjetivo.com CNAME . -foundationrepairhoustontx.net CNAME . foxeps.com.br CNAME . fraud.bpcbankingtech.com CNAME . freecnetdownload.com CNAME . @@ -424,7 +425,6 @@ ftp.n3twork30cm.ml CNAME . fullelectronica.com.ar CNAME . funletters.net CNAME . fusionfiresolutions.com CNAME . -futbolpr.com CNAME . futuregraphics.com.ar CNAME . g.pinmonkey.xyz CNAME . gametwogame.com CNAME . @@ -441,6 +441,7 @@ ghettohub.co.za CNAME . ghislain.dartois.pagesperso-orange.fr CNAME . giadungg7.com CNAME . giddos.ga CNAME . +giteletropical.com CNAME . glowinmedia.co.ke CNAME . gmsebpl.com CNAME . gmtransformationacademy.com CNAME . @@ -453,6 +454,7 @@ goldcoastoffice365.com CNAME . goldcoastoffice365.com.au CNAME . golden-memories-funerals.yourpageserver.com CNAME . goldenasiacapital.com CNAME . +goldmen.in CNAME . gorecycle.fahadjutt.com CNAME . gpotecnosystems.com CNAME . gracejukes.com CNAME . @@ -481,13 +483,12 @@ hhaward.org CNAME . highlandroadcoc.com CNAME . highlandslasvegas.atakdev.com CNAME . hindi.factsriver.com CNAME . -hiptool.net CNAME . hitpe.com CNAME . hitstation.nl CNAME . +hlmd.in CNAME . hmpmall.co.kr CNAME . hoagietesting10.com CNAME . hoayeuthuong-my.sharepoint.com CNAME . -holmesservices.mobiledevsite.co CNAME . homefindersolutions.com CNAME . hongluosi.com CNAME . hookedupboatclub.com CNAME . @@ -498,7 +499,6 @@ houstonshutters.site CNAME . hr2019.vrcom7.com CNAME . hrnautica.com.br CNAME . hseda.com CNAME . -hsmwebapp.com CNAME . htownbars.com CNAME . hubtech.co.za CNAME . huellacero.cl CNAME . @@ -538,16 +538,19 @@ ioabc.wif.com.br CNAME . ipmes.ma CNAME . iremart.es CNAME . iris101.co.uk CNAME . +isaac.mikhailmotoringschool.com CNAME . iscamenabe.com CNAME . isiphephelocon.co.za CNAME . iso-dubai.net CNAME . israrulhaq.me CNAME . +isrorg.com CNAME . isso.ps CNAME . ist-security.com CNAME . it123.ru CNAME . italiandirezione.casa CNAME . itc-demo.softgig.co.ke CNAME . itelsys.ma CNAME . +itmotasaciones.com CNAME . jacktech.jackindia.com CNAME . jaishritours.com CNAME . jamiekaylive.com CNAME . @@ -561,6 +564,7 @@ jennwolfemtb.com CNAME . jhayesconsulting.com CNAME . jiaoyuzixun.cn CNAME . jing-da.com.tw CNAME . +jmtc.91756.cn CNAME . jnanbharati.com CNAME . jobs.thebeessolution.com CNAME . joelbonissilver.com CNAME . @@ -571,6 +575,7 @@ jumpmanualjacobhiller.com CNAME . jupiter.toxsl.in CNAME . justinscott.com.au CNAME . kadigital.co.uk CNAME . +kaizenjanitorial.com CNAME . kalawatihomes.com CNAME . kalogirosfinance.com CNAME . kaptaanchapal.com CNAME . @@ -632,14 +637,16 @@ lotusanddragonfly.com CNAME . lp.definerisco.com CNAME . lp.difusodesign.com CNAME . lp.quama.pe CNAME . -ltc.typoten.com CNAME . +luckybrownie.com CNAME . luminouspneuma.com CNAME . luxomodels.com CNAME . m-technics.kz CNAME . m.estudiomoros.com.ar CNAME . m.mobilelocalsales.com CNAME . +m.softsharks.com CNAME . madicon.co.za CNAME . magianegramagiablancayamarres.com CNAME . +maharaniworld.com CNAME . mail.bs-eiendomme.co.za CNAME . mail.golimoapp.com CNAME . mail.jeffsono.org CNAME . @@ -665,7 +672,6 @@ matruchhaya.co.in CNAME . maxiquim.cl CNAME . maxoprint.co.uk CNAME . maxtox.com.pk CNAME . -maybethescobar.com CNAME . mbgrm.com CNAME . mbjtimes.com CNAME . mbsolutions.ge CNAME . @@ -696,11 +702,12 @@ michaelphilip.com CNAME . michimal2.000webhostapp.com CNAME . microblading.mirliandias.com.br CNAME . microcomm-group.com CNAME . +mikhailmotoringschool.com CNAME . +mills-skyla30ec.com CNAME . mingguanwms.com CNAME . minuevavida.org CNAME . mirror.mypage.sk CNAME . misterson.com CNAME . -mixr.at CNAME . mkontakt.az CNAME . mktf.mx CNAME . mmdx.com CNAME . @@ -737,6 +744,7 @@ navayurveda.in CNAME . nec-i.com CNAME . nedkellymyanmar.com CNAME . nelitrianggraeni.000webhostapp.com CNAME . +nellaimasthanbiryani.com CNAME . nerve.untergrund.net CNAME . nettube.com.br CNAME . networkwheels.co.za CNAME . @@ -761,7 +769,6 @@ njtiledesigncenter.com CNAME . nobius.org CNAME . nocalnoodle.elin.co.za CNAME . nomadicbees.com CNAME . -nonnarina.ax CNAME . notamuzikaletleri.com CNAME . ns1.the-widyantos.com CNAME . nsb.org.uk CNAME . @@ -781,12 +788,15 @@ omaromatic.com CNAME . omega.az CNAME . oms.pappai.com CNAME . omscoc.pappai.com CNAME . +onedigitalcard.granvizionnecorp.com CNAME . onedrive.listifyapp.co CNAME . online.creedglobal.in CNAME . onlinestatis.bar CNAME . +open.rawntech.com CNAME . open.warehousesaas.co.uk CNAME . opentoronto.org CNAME . opolis.io CNAME . +opticaoptigral.cl CNAME . optimus.com.sg CNAME . order.bizpeed.com CNAME . orientgatewayltd.com CNAME . @@ -824,6 +834,7 @@ pcsoori.com CNAME . pd.oceaniarp.net CNAME . pemdodo.com CNAME . perfumeriamontes.es CNAME . +periodiche.bar CNAME . perpus.onlineman7-jombang.sch.id CNAME . perpustekim.untirta.ac.id CNAME . pestoclean.co.uk CNAME . @@ -843,6 +854,7 @@ pmglance.startwriteup.com CNAME . pointactionsg.com CNAME . pokojewewladyslawowie.pl CNAME . pole.com.vc CNAME . +ponchokhana.com CNAME . pool.phxdir.com CNAME . pooltablemoversdenver.net CNAME . portal.premiumpunch.com CNAME . @@ -853,6 +865,7 @@ prestasicash.com.ar CNAME . prestigehomeautomation.net CNAME . preview2.behalen.com CNAME . prishaartcreations.com CNAME . +prismaxis.com CNAME . production.sparshims.com CNAME . programaoperadoronline.com.br CNAME . project.exquitec.com CNAME . @@ -904,7 +917,6 @@ reseller.itechbrasil.com CNAME . resuco.net CNAME . rezkabum.ru CNAME . rhema.com.sg CNAME . -richancyber.info CNAME . richmondminerals.co.zm CNAME . rinaefoundation.org.za CNAME . rinkaisystem-ht.com CNAME . @@ -913,7 +925,6 @@ rkcable.co.in CNAME . rkverify.securestudies.com CNAME . robertmcardle.com CNAME . robertsinclair.net CNAME . -romanianpoints.com CNAME . ronnietucker.co.uk CNAME . roomsvc.servegate.kr CNAME . roshnijewellery.com CNAME . @@ -923,7 +934,6 @@ rubycityvietnam.com CNAME . ruisgood.ru CNAME . ruwadalkuwait.com CNAME . rydchile.cl CNAME . -s.51shijuan.com CNAME . s.thechinesemuslim.com CNAME . sac2.11xii.com CNAME . sacredscentsonline.com CNAME . @@ -957,7 +967,9 @@ serendibsourcing.com CNAME . sericaasia.com CNAME . servicemhkd.myvnc.com CNAME . servicemhkd80.myvnc.com CNAME . +serviciovirtual.com.ar CNAME . sexologistpakistan.net CNAME . +seyranikenger.com.tr CNAME . sgb.ac.ke CNAME . sgessy.com.br CNAME . shaheentbfoundation.com CNAME . @@ -1008,6 +1020,7 @@ spaceframe.mobi.space-frame.co.za CNAME . special-key.cf CNAME . spent.com.pl CNAME . spetsesyachtcharter.gr CNAME . +spiritualroot.org CNAME . spititourism.com CNAME . spittinfire.com CNAME . sports-net.de CNAME . @@ -1027,7 +1040,7 @@ stiepancasetia.ac.id CNAME . stlukesohag.com CNAME . store.ericalgarin.com CNAME . stott-thompson.co.uk CNAME . -streetdemo.yourpageserver.com CNAME . +stratexec.co.za CNAME . suboldesign.com CNAME . sumerians.org CNAME . sunaryem.com.tr CNAME . @@ -1075,6 +1088,7 @@ test.lubrico.in CNAME . test.typoten.com CNAME . test.wanepghana.org CNAME . test1.asistencia247.com CNAME . +test1.milenial.id CNAME . test1.tenplusone.my CNAME . test2.basis-web.com CNAME . test2.marrenconstruction.ie CNAME . @@ -1099,7 +1113,7 @@ themansionkasauli.com CNAME . theprofinn.com CNAME . thesummitpc.net CNAME . theurbantutors.com CNAME . -thientu.net CNAME . +thirdstringcalifornia.com CNAME . thosewebbs.com CNAME . thriveink.com CNAME . tianangdep.com CNAME . @@ -1109,7 +1123,6 @@ timamollo.co.za CNAME . timegonebuy.com CNAME . tksb.net CNAME . tlcc.com.gt CNAME . -tntmedia.gr CNAME . todoapp.cstdevs.com CNAME . todocontodo.com.mx CNAME . tonydong.com CNAME . @@ -1146,6 +1159,7 @@ ultimate-24.de CNAME . umwelt-kirchhof.de CNAME . unicorpbrunei.com CNAME . uniengrisb.com CNAME . +unisoftcc.com CNAME . unyazitelecom.com CNAME . upcbpta.com CNAME . urbantrapfest.cl CNAME . @@ -1160,7 +1174,9 @@ vbcargo.hu CNAME . vcah.co.uk CNAME . vectarts.com CNAME . vegadelcasero.cl CNAME . +velma-harber30ku.com CNAME . vendas.lidiacarmeli.com.br CNAME . +versualstudio.com CNAME . veterinariadrpopui.com CNAME . vfocus.net CNAME . vienen.gblix.srv.br CNAME . @@ -1187,6 +1203,7 @@ vvsskmodinationalschool.com CNAME . w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu CNAME . wanepliberia.org CNAME . wanepniger.org CNAME . +weareactum.com CNAME . web.eng.ubu.ac.th CNAME . web.geetle.ga CNAME . web.geomegasoft.net CNAME . @@ -1214,6 +1231,7 @@ wolfgang-brodte.de CNAME . wonderhawaii.com CNAME . woodsytech.com CNAME . wordpress.saleensuporte.com.br CNAME . +workingsolutionsrome.org CNAME . wozata.000webhostapp.com CNAME . wp.readhere.in CNAME . wpdemo.101clients.com.au CNAME . @@ -1235,7 +1253,6 @@ yoast.yourpageserver.com CNAME . yourclub1.com CNAME . yourtopdog.com.au CNAME . youtubetrainingacademy.com CNAME . -yp.hnggzyjy.cn CNAME . yskadvisors.com CNAME . yummyyogaudaipur.com CNAME . yzkzixun.com CNAME . diff --git a/urlhaus-filter-rpz.conf b/urlhaus-filter-rpz.conf index e794ca82..3b0e2db8 100644 --- a/urlhaus-filter-rpz.conf +++ b/urlhaus-filter-rpz.conf @@ -1,12 +1,12 @@ ; Title: Malicious Domains RPZ Blocklist -; Updated: Sat, 03 Apr 2021 00:13:46 UTC +; Updated: Sat, 03 Apr 2021 12:12:28 UTC ; Expires: 1 day (update frequency) ; Homepage: https://gitlab.com/curben/urlhaus-filter ; License: https://gitlab.com/curben/urlhaus-filter#license ; Source: https://urlhaus.abuse.ch/api/ $TTL 30 -@ IN SOA rpz.curben.gitlab.io. hostmaster.rpz.curben.gitlab.io. 1617408838 86400 3600 604800 30 +@ IN SOA rpz.curben.gitlab.io. hostmaster.rpz.curben.gitlab.io. 1617451959 86400 3600 604800 30 NS localhost. 0-24bpautomentes.hu CNAME . @@ -243,7 +243,6 @@ $TTL 30 123moviesfx.com CNAME . 123sellfast.com CNAME . 123sex.co CNAME . -123tadi.com CNAME . 123xyz.xyz CNAME . 124.com.ua CNAME . 124.cpanel.realwebsitesite.com CNAME . @@ -7099,7 +7098,6 @@ app.bigplan-alex.com CNAME . app.boxrcdn.com CNAME . app.bridgeimpex.org CNAME . app.calag.at CNAME . -app.casetabs.com CNAME . app.catholicchurch.co.in CNAME . app.choiphui.com CNAME . app.cloudindustry.net CNAME . @@ -11331,6 +11329,7 @@ beanmatrix.com CNAME . beansmedia.com CNAME . beanssur.com CNAME . beantreefoods.com CNAME . +beanx88.xyz CNAME . beanz-network.com CNAME . bearcatpumps.com.cn CNAME . beard-companies.com CNAME . @@ -17632,7 +17631,6 @@ cdncomfortgroup.website CNAME . cdndownloadlp.club CNAME . cdnmultimedia.com CNAME . cdnpic.mgyun.com CNAME . -cdnrep.reimageplus.com CNAME . cdnxh.net CNAME . cdoconsult.com.br CNAME . cdolechon.com CNAME . @@ -18375,7 +18373,6 @@ cheapesthost.com.ng CNAME . cheapgadgets-gq.000webhostapp.com CNAME . cheapistan.pk CNAME . cheapmlbjerseysmarlins.com CNAME . -cheapmusic.info CNAME . cheapoakleysunglasses.net CNAME . cheappigeontraps.com CNAME . cheapraccoontraps.com CNAME . @@ -18424,7 +18421,6 @@ cheekie2.neagoeandrei.com CNAME . cheematransxpressinc.com CNAME . cheerchile.cl CNAME . cheerfulgiversneverlack.com CNAME . -cheerfullydo.com CNAME . cheesecakery.com.br CNAME . cheetahridge.mediadevstaging.com CNAME . chef-solutions.dreamscape.co.in CNAME . @@ -18863,6 +18859,7 @@ christina.makeyourselfelaborate.com CNAME . christinablunsum.com CNAME . christinailoveyousomuchyoumyheart.duckdns.org CNAME . christinalenway.com CNAME . +christinekeller.ch CNAME . christinelebeck.com CNAME . christinmunsch.com CNAME . christmasatredeemer.org CNAME . @@ -24433,6 +24430,7 @@ demo.jjmayurved.com CNAME . demo.jrkcompany.com CNAME . demo.kalapifoods.com CNAME . demo.kanapebudapest.hu CNAME . +demo.kechuahangdidong.com CNAME . demo.kzonetechnologies.com CNAME . demo.lamppostmedia.in CNAME . demo.lapizblanco.com CNAME . @@ -26497,7 +26495,6 @@ dl-45538429.onedrives-en-live.com CNAME . dl-675423.store-downloads.com CNAME . dl-80076342.md-downloads.com CNAME . dl-97674424.md-downloads.com CNAME . -dl-gameplayer.dmm.com CNAME . dl-link.link CNAME . dl-link.live CNAME . dl-link.network CNAME . @@ -26528,7 +26525,6 @@ dl.repairlabshost.com CNAME . dl.rina-roleplay.com CNAME . dl.river-store.com CNAME . dl.rp-soft.ir CNAME . -dl.softservers.net CNAME . dl.svcupdate.com CNAME . dl.teeqee.com CNAME . dl.x420.me CNAME . @@ -27331,8 +27327,10 @@ down.pcclear.com CNAME . down.post-gg.top CNAME . down.postch-b.top CNAME . down.postch-bsw.top CNAME . +down.postch-de.top CNAME . down.postch-dfa.top CNAME . down.postch-dj.top CNAME . +down.postch-dl.top CNAME . down.postch-fa.top CNAME . down.postch-fj.top CNAME . down.postch-kf.top CNAME . @@ -29143,7 +29141,6 @@ economiadeltempo.it CNAME . economiadigital.biz CNAME . economika.com.ve CNAME . economizei.shop CNAME . -economplast.com CNAME . economywindowcleaner.com CNAME . econoteen.fea.usp.br CNAME . econotel.us CNAME . @@ -33852,7 +33849,6 @@ files.danwin1210.me CNAME . files.dropmybin.me CNAME . files.enjin.com CNAME . files.gathercdn.com CNAME . -files.hrloo.com CNAME . files.l-d.tech CNAME . files.martellexpress.us CNAME . files.mirai-2viv.vn CNAME . @@ -36065,6 +36061,7 @@ fuzzymiles.com CNAME . fv1-2.failiem.lv CNAME . fv13.failiem.lv CNAME . fv15.failiem.lv CNAME . +fv2-2.failiem.lv CNAME . fv2-7.failiem.lv CNAME . fv3.failiem.lv CNAME . fv6.failiem.lv CNAME . @@ -40308,7 +40305,6 @@ hangtotma.com CNAME . hangtrentroi.com CNAME . hangulcafes.ga CNAME . hanh.cz CNAME . -hanhtrinhtamlinh.com CNAME . hanhtrinhthanhnienkhoinghiep.vn CNAME . haniamarket.com CNAME . hanict.org.vn CNAME . @@ -40503,7 +40499,6 @@ harrisburgprinting.com CNAME . harriscustomcatering.com CNAME . harrisheatpumps.nz CNAME . harrisnewtech.ir CNAME . -harrisoncarter.com CNAME . harrisonlily.co.uk CNAME . harryfang.com CNAME . harryhiggins.com CNAME . @@ -43304,7 +43299,6 @@ i-sharecloud.com CNAME . i-supportcharity.com CNAME . i-vnsweyu.pl CNAME . i-voda.com CNAME . -i.fiery.me CNAME . i.fluffy.cc CNAME . i.funtourspt.eu CNAME . i.ooxx.ooo CNAME . @@ -49685,6 +49679,7 @@ kebunrayabaturraden.id CNAME . kec-cendana.enrekangkab.go.id CNAME . kec-wlingi.blitarkab.go.id CNAME . kecforging.com CNAME . +kechuahangdidong.com CNAME . keciorenkoltukyikama.net CNAME . keckarangdadap.pekalongankab.go.id CNAME . kecsfila.hu CNAME . @@ -67488,6 +67483,7 @@ osrsport.com CNAME . ossandonycia.cl CNAME . osscaar.com CNAME . osservatore.betacom.it CNAME . +ossi4.51cto.com CNAME . ossianlaw.com CNAME . osslusturv.com CNAME . ossoriobouliz.com CNAME . @@ -70820,6 +70816,7 @@ politinsky.000webhostapp.com CNAME . politrix.net CNAME . poliyzsl.host CNAME . poljimenez.com CNAME . +polk.k12.ga.us CNAME . polka32.ru CNAME . polkapower.com CNAME . polkolonieb4k.pl CNAME . @@ -71991,7 +71988,6 @@ professionalshop.in CNAME . professionalwaiterskollege.org CNAME . professionelelit.com CNAME . professorsgallery.com CNAME . -profetestruec.net CNAME . profexsystem.com CNAME . proffessia.ru CNAME . proffice.com.pl CNAME . @@ -72369,6 +72365,7 @@ protech.binarybizz.com CNAME . protech.mn CNAME . protechcarpetcare.com CNAME . protechgroup1.com CNAME . +protect.mimecast-offshore.com CNAME . protectiadatelor.biz CNAME . protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org CNAME . protection.pecol.eu CNAME . @@ -80475,7 +80472,6 @@ shareallfilesthroughsecureexchangesystem.duckdns.org CNAME . sharebook.tk CNAME . sharechautari.com CNAME . shared-cnd.com CNAME . -shared.pdffiller.com CNAME . shareddocuments.ml CNAME . shareddynamics.com CNAME . sharedeconomy.eu CNAME . @@ -86104,6 +86100,7 @@ sup3rc10ud.ga CNAME . supadom.fr CNAME . supamidland-my.sharepoint.com CNAME . supcargo.com CNAME . +supdate.mediaweb.co.kr CNAME . super-filtr.ru CNAME . super-gamezer.com CNAME . super-industries.co CNAME . @@ -90722,7 +90719,6 @@ tlcmoto.com CNAME . tldrbox.top CNAME . tlextreme.com CNAME . tlfthelifefactory.com.au CNAME . -tlgur.com CNAME . tlkcloudem.com CNAME . tlktdsfj.sha58.me CNAME . tlpclient.site CNAME . @@ -92358,6 +92354,7 @@ tsport88.com CNAME . tsr-mark.xyz CNAME . tsredco.telangana.gov.in CNAME . tsrj.monster CNAME . +tsrv2.top CNAME . tst.marineindust.com CNAME . tstfrigo.com CNAME . tsugite.youbi.me CNAME . @@ -93769,6 +93766,7 @@ update-chase.justmoveup.com CNAME . update-prog.com CNAME . update-res.100public.com CNAME . update.5v.pl CNAME . +update.7h4uk.com CNAME . update.att.tools CNAME . update.bracncet.net CNAME . update.bruss.org.ru CNAME . @@ -94008,6 +94006,7 @@ url-update.com CNAME . url-validation-clients.com CNAME . url.246546.com CNAME . url.57569.fr.snd52.ch CNAME . +url2.mailanyone.net CNAME . url3.mailanyone.net CNAME . url5459.41southbar.com CNAME . url675.textilmallorca.com CNAME . @@ -95406,7 +95405,6 @@ viettrungkhaison.com CNAME . viettrust-vn.net CNAME . vietucgroup.org CNAME . vietup.net CNAME . -vietvictory.vn CNAME . vievioparapija.eu CNAME . view-indonesia.com CNAME . view-your-website.com CNAME . @@ -95860,6 +95858,7 @@ visual-sounds.com CNAME . visualblends.com CNAME . visualdata.ru CNAME . visualdimensioniq.com CNAME . +visualdive.com CNAME . visualendodontics.net CNAME . visualgag.co.uk CNAME . visualhome.cl CNAME . @@ -96938,7 +96937,6 @@ wc2018.top CNAME . wc3prince.ru CNAME . wcare.nl CNAME . wcbgroup.co.uk CNAME . -wcdownloadercdn.lavasoft.com CNAME . wcdr.pbas.es CNAME . wcf-old.sibcat.info CNAME . wcfamlaw.com CNAME . @@ -98604,6 +98602,7 @@ workingin-my.sharepoint.com CNAME . workingonit.site CNAME . workingpainters.com CNAME . workingroofers.com CNAME . +workingsolutionsrome.org CNAME . workingwell.club CNAME . worklinic.com.br CNAME . workmate-sien.com CNAME . @@ -100970,7 +100969,6 @@ yoyoplease.com CNAME . yoyoso.nz CNAME . yoyoteacher.cn CNAME . yp.dcyazilim.com CNAME . -yp.hnggzyjy.cn CNAME . ypbb.or.id CNAME . ypddf.org CNAME . ypicsdy.cf CNAME . @@ -101919,6 +101917,7 @@ zoovetdv.ru CNAME . zoox.com.br CNAME . zoparo.nl CNAME . zopbxtjiuykhyyp.usa.cc CNAME . +zopro.duckdns.org CNAME . zoracle.com CNAME . zorancreative.com CNAME . zoratech.ro CNAME . diff --git a/urlhaus-filter-snort2-online.rules b/urlhaus-filter-snort2-online.rules index d49c98b7..82c2ce0e 100644 --- a/urlhaus-filter-snort2-online.rules +++ b/urlhaus-filter-snort2-online.rules @@ -1,5 +1,5 @@ # Title: Online Malicious URL Snort2 Ruleset -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -7,40 +7,40 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"0-24bpautomentes.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100000001; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"0cl.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100000002; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.11.234.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000003; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.222.196.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000004; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.245.4.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000005; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000006; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000007; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000008; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000009; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000010; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000011; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000012; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000013; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.186.151.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000004; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.222.196.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000005; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.245.4.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000006; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000007; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000008; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000009; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000010; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000011; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000012; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000013; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000014; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000015; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000016; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000017; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000018; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000019; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000020; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000021; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000022; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000023; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000024; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000025; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000026; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000027; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000028; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000029; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000030; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000031; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000032; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000033; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000034; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000035; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000036; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000037; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000017; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000018; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000019; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000020; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000021; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000022; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000023; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000024; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000025; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000026; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000027; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000028; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000029; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000030; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000031; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000032; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000033; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000034; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000035; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000036; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000037; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000038; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000039; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000040; rev:1;) @@ -78,4328 +78,4206 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.73.131.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100000072; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.75.157.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000073; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.75.167.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000074; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.99.94.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000075; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.130.115.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000076; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.141.240.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000077; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.113.99.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000078; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.125.218.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000079; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.136.82.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000080; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.141.138.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000081; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.141.138.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000082; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.146.174.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000083; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.16.145.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000084; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.204.168.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000085; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.217.215.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000086; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.224.200.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000087; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.224.200.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000088; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.227.118.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000089; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.238.228.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000090; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.249.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000091; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.4.117.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000092; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.70.160.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000093; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.79.112.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000094; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.82.98.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000095; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.240.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000096; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000097; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000098; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000099; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000100; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000101; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000102; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000103; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000104; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000105; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000106; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.97.184.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000107; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.168.98.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000108; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.184.75.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000109; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.206.93.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000110; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.33.52.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000111; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.61.86.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000112; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.1.111.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000113; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.104.172.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000114; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.104.193.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000115; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.105.33.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000116; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.165.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000117; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.193.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000118; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.249.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000119; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.155.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000120; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.219.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000121; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.250.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000122; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.61.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000123; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.197.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000124; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.31.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000125; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.33.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000126; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.181.136.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000127; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.189.8.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000128; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.194.242.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000129; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.219.185.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000130; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.220.119.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000131; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.221.96.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000132; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.201.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000133; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.250.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000134; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.55.199.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000135; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.124.90.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000136; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.233.196.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000137; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.235.7.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000138; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.86.85.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000139; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000140; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000141; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.127.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000142; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.57.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000143; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.99.37.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000144; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.10.58.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000145; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.14.58.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000146; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.187.229.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000147; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.228.190.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000148; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.228.195.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000149; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.241.119.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000150; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.124.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000151; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.251.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000152; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.251.10.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000153; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.150.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000154; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.213.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000155; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.130.115.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000075; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.141.240.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000076; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.113.99.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000077; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.125.218.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000078; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.141.138.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000079; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.141.138.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000080; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.146.174.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000081; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.16.145.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000082; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.204.168.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000083; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.217.215.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000084; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.224.200.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000085; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.224.200.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000086; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.237.21.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000087; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.238.228.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000088; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.249.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000089; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.4.117.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000090; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.70.160.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000091; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.82.98.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000092; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.240.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000093; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000094; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000095; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000096; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000097; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000098; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000099; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000100; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000101; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000102; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000103; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.97.184.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000104; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.168.98.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000105; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.184.75.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000106; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.206.93.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000107; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.33.52.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000108; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.61.86.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000109; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.1.111.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000110; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.104.172.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000111; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.104.193.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000112; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.105.33.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000113; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.165.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000114; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.193.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000115; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.249.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000116; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.155.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000117; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.219.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000118; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.250.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000119; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.61.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000120; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.197.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000121; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.31.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000122; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.33.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000123; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.181.136.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000124; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.189.8.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000125; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.194.242.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000126; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.219.185.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000127; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.220.119.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000128; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.221.96.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000129; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.201.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000130; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.250.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000131; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.55.199.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000132; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.124.90.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000133; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.233.196.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000134; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.235.7.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000135; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.248.58.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000136; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.86.85.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000137; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000138; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000139; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.127.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000140; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.57.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000141; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.99.37.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000142; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.10.58.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000143; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.14.58.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000144; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.187.229.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000145; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.228.190.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000146; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.228.195.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000147; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.241.119.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000148; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.124.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000149; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.175.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000150; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.251.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000151; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.251.10.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000152; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.150.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000153; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.213.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000154; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.51.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000155; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.255.101.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000156; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.255.167.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000157; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.145.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000158; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.208.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000159; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.221.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000160; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.223.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000161; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.225.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000162; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.233.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000163; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.235.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000164; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.4.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000165; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110fss.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100000166; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.111.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000167; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.41.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000168; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.88.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000169; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.119.245.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000170; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.125.67.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000171; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.165.21.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000172; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.165.248.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000173; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.166.236.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000174; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.167.151.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000175; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.85.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000176; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.86.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000177; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.172.57.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000178; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.182.235.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000179; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.171.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000180; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.177.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000181; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.23.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000182; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.230.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000183; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.27.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000184; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.49.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000185; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000186; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000187; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.104.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000188; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.104.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000189; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000190; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000191; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000192; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000193; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000194; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000195; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000196; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.61.52.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000197; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.108.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000198; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.31.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000199; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.133.222.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000200; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.147.92.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000201; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.159.108.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000202; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.163.200.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000203; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.124.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000204; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.233.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000205; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.210.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000206; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.96.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000207; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.187.91.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000208; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.214.127.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000209; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.187.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000210; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.236.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000211; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.239.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000212; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.43.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000213; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.118.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000214; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.202.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000215; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.67.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000216; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.180.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000217; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.79.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000218; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.79.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000219; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.178.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000220; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.188.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000221; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.230.168.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000222; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.218.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000223; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.235.149.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000224; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.235.188.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000225; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.171.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000226; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.141.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000227; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.144.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000228; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.197.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000229; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.209.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000230; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.75.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000231; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.143.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000232; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.17.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000233; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.190.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000234; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.227.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000235; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.39.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000236; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.73.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000237; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.240.216.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000238; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.152.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100000239; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.2.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000240; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.243.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000241; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.12.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000242; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.8.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000243; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.126.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000244; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.162.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000245; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.180.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000246; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.51.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000247; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.100.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000248; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.121.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000249; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.16.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000250; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.191.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000251; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.214.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000252; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.240.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000253; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.25.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000254; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.8.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000255; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.81.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000256; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.82.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000257; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000258; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.179.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000259; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.197.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000260; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.109.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000261; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.118.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000262; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.26.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000263; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.79.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000264; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.250.102.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000265; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.250.57.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000266; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.218.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000267; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.136.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000268; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.196.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000269; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.212.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000270; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.221.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000271; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.239.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000272; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.254.208.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000273; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.254.32.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000274; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.38.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000275; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.6.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000276; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.8.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000277; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.121.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000278; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000279; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000280; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000281; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000282; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000283; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000284; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000285; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000286; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000287; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000288; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000289; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000290; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000291; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000292; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000293; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000294; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000295; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000296; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000297; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000298; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000299; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000300; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000301; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000302; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000303; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000304; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000305; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000306; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.127.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000307; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000308; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000309; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.85.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000310; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.87.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000311; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.88.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000312; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000313; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000314; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000315; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000316; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000317; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000318; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000319; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000320; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000321; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000322; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000323; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000324; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000325; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000326; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000327; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000328; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000329; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000330; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000331; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000332; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000333; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000334; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000335; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000336; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.35.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000337; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.38.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000338; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000339; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000340; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000341; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000342; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000343; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000344; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.240.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000345; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.82.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000346; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.87.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000347; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.224.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000348; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.65.53.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000349; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000350; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000351; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000352; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000353; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.231.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000354; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.78.45.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000355; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.117.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000356; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.118.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000357; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.127.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000358; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.207.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000359; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.215.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000360; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.146.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000361; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.18.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100000362; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.224.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000363; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.93.29.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000364; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.11.95.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000365; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.144.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000366; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.122.238.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000367; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.161.58.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000368; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.161.78.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000369; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.172.250.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000370; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.195.163.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000371; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.226.42.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000372; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.194.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000373; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.35.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000374; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.211.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000375; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.254.169.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000376; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.128.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000377; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.136.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000378; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.154.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000379; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.191.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000380; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.61.204.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000381; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.87.174.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000382; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.87.175.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000383; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.89.42.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000384; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.89.43.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000385; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.90.26.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000386; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.199.204.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000387; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.200.154.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000388; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.224.203.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000389; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.226.100.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000390; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.228.205.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000391; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.229.165.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000392; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.235.115.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000393; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.30.54.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000394; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.32.237.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000395; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.79.172.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000396; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.165.216.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000397; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.201.38.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000398; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.42.47.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000399; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.204.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000400; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.21.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000401; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.125.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000402; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.18.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000403; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.144.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000404; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.145.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000405; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.153.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000406; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.190.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000407; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.60.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000408; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.131.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000409; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.133.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000410; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.144.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000411; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.159.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000412; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.187.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000413; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.132.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000414; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.165.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000415; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.240.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000416; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.255.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000417; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.118.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000418; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.62.26.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000419; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.73.3.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000420; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.92.174.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000421; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.124.219.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000422; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.132.151.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000423; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.206.164.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000424; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.211.100.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000425; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.212.132.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000426; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.212.142.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000427; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.196.49.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000428; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.196.50.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000429; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000430; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000431; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.210.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000432; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.236.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000433; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.243.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000434; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.200.76.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000435; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.26.110.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000436; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.113.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000437; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.195.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000438; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.53.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000439; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.86.105.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000440; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.104.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000441; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.157.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000442; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.7.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000443; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.32.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000444; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.5.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000445; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.72.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000446; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.12.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000447; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.128.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000448; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.208.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000449; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.209.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000450; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.214.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000451; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.88.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000452; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000453; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000454; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.221.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000455; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.63.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000456; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.65.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000457; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.42.125.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000458; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.43.180.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000459; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.125.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000460; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.218.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000461; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.50.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000462; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.58.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000463; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.96.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000464; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.83.79.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000465; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.91.24.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000466; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.179.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000467; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.183.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000468; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.239.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000469; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.108.161.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000470; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.112.185.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000471; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.119.63.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000472; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.14.143.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000473; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.147.213.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000474; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.163.93.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000475; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.18.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000476; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.218.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000477; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.107.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000478; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.163.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000479; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.174.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000480; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.197.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000481; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.241.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000482; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.27.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000483; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.68.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000484; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.170.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000485; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.97.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000486; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.26.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000487; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.177.147.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000488; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.248.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000489; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.157.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000490; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.16.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000491; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.170.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000492; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.43.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000493; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.75.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000494; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.18.38.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000495; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.106.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000496; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.108.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000497; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.108.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000498; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.33.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000499; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.94.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000500; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.119.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000501; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.124.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000502; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.182.97.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000503; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.183.115.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000504; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.14.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000505; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.172.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000506; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.195.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000507; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.245.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000508; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.137.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000509; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.227.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000510; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.150.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000511; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.187.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000512; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.215.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000513; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.240.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000514; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.204.30.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000515; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.250.129.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000516; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.105.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000517; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.14.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000518; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.131.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000519; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000520; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000521; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.144.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000522; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.148.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000523; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.155.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000524; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.172.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000525; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.175.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000526; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.195.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000527; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.206.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000528; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.232.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000529; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.132.113.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000530; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.15.69.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000531; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000532; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000533; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000534; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000535; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.207.39.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000536; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.25.204.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000537; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.0.255.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000538; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.12.153.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000539; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.142.222.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000540; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.150.213.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000541; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.151.248.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000542; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000543; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000544; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000545; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000546; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000547; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000548; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000549; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000550; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000551; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000552; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000553; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000554; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000555; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.121.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000556; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000557; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000558; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.127.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000559; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.99.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000560; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.210.89.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000561; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.43.33.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000562; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.5.15.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000563; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.66.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000564; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.93.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000565; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.141.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000566; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.8.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000567; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.7.75.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000568; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.173.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000569; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.174.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000570; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.210.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000571; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.114.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000572; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.96.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000573; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.121.44.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000574; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.122.71.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000575; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.123.53.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000576; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.127.155.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000577; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.141.11.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000578; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.15.142.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000579; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.159.22.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000580; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.170.234.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000581; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.185.31.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000582; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.190.36.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000583; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.20.104.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000584; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.225.11.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000585; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.23.57.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000586; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.230.171.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000587; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.231.103.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000588; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.237.226.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000589; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.239.15.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000590; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.24.116.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000591; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.25.101.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000592; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.254.43.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000593; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.254.76.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000594; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.101.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000595; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.98.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000596; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.88.99.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000597; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.100.150.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000598; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.159.178.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000599; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.160.147.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000600; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.176.44.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000601; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.188.86.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000602; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.66.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000603; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.72.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000604; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.79.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000605; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.83.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000606; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.37.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000607; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.41.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000608; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.29.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000609; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.33.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000610; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.0.240.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000611; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.54.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000612; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000613; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000614; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.170.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000615; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000616; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.19.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000617; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.200.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000618; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.238.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000619; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.128.133.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000620; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.129.84.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000621; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.208.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000622; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.23.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000623; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.27.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000624; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.37.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000625; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.61.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000626; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.77.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000627; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.131.186.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000628; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.132.219.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000629; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.125.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000630; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.98.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000631; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.134.14.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000632; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.134.50.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000633; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.120.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000634; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.199.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000635; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.153.80.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000636; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.116.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000637; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.236.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000638; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.94.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000639; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.156.136.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000640; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.8.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000641; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.183.121.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000642; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.191.150.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000643; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.191.164.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000644; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.101.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000645; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.194.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000646; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.149.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000647; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.53.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000648; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.235.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000649; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.35.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000650; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.52.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000651; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.60.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000652; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.112.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000653; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.184.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000654; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.98.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000655; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.212.29.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000656; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.213.225.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000657; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.130.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000658; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.152.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000659; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.116.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000660; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.184.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000661; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.235.226.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000662; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.103.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000663; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.181.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000664; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.79.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000665; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.148.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000666; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.184.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000667; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.28.217.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000668; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.189.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000669; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.5.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000670; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.184.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000671; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.119.108.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000672; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.221.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000673; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.76.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000674; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.130.110.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100000675; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.130.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000676; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.104.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000677; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.151.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000678; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.203.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000679; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.24.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000680; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000681; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.54.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000682; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.132.110.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000683; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.135.34.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000684; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.136.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000685; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.236.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000686; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.160.126.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000687; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.163.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000688; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.65.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000689; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.72.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000690; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.165.123.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000691; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.187.111.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000692; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.199.56.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000693; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.230.174.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000694; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.254.251.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000695; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.5.92.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000696; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.6.0.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000697; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.67.89.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000698; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.7.254.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000699; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.80.46.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000700; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.91.135.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000701; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.91.237.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000702; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.93.94.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000703; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.128.28.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000704; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.142.93.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000705; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.191.113.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000706; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.1.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000707; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.73.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000708; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.75.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000709; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.215.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000710; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.53.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000711; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.63.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100000712; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.129.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000713; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.79.200.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000714; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"128.116.133.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000715; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"130.255.159.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000716; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"134.195.139.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000717; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"135.148.36.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000718; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"138.99.204.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100000719; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.159.226.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000720; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.170.173.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000721; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.216.102.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000722; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.227.46.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000723; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.102.17.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000724; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.136.80.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000725; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000726; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.178.163.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000727; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.189.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000728; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.37.222.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000729; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.45.127.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000730; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.25.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000731; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.98.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000732; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.55.29.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000733; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"141.105.65.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000734; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.11.216.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000735; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.177.56.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000736; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"146.71.79.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000737; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"148.69.108.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000738; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.20.176.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000739; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000740; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000741; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000742; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000743; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000744; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.3.124.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000745; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.3.85.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000746; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14karatvisions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100000747; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"150.116.207.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000748; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.177.163.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000749; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.33.230.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000750; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.234.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100000751; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.47.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000752; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.152.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000753; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.135.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000754; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.36.126.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000755; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"155.138.134.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100000756; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.101.165.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000757; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.174.213.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000758; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.247.195.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000759; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.51.125.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000760; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"159.224.74.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000761; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.194.28.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000762; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.209.98.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000763; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.53.206.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000764; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"165.90.16.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000765; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"168.205.223.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000766; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"170.81.238.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000767; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.113.36.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100000768; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.113.38.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000769; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.121.255.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000770; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.112.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000771; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.114.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000772; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.176.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000773; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.179.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000774; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.162.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000775; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.174.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000776; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.105.36.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000777; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.114.244.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000778; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000779; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000780; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.81.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000781; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.93.194.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000782; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.167.85.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000783; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.169.46.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000784; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.19.58.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000785; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.233.85.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000786; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.235.209.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000787; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.25.113.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000788; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.95.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000789; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.97.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000790; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.119.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000791; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.92.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100000792; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.106.33.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000793; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.48.181.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000794; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.61.3.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000795; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.73.246.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000796; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.81.78.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000797; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.83.73.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000798; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.10.147.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100000799; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.11.193.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000800; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.11.65.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000801; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.117.66.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000802; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.145.200.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100000803; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.169.13.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000804; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.201.104.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000805; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.208.230.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000806; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.212.6.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100000807; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.42.46.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000808; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.9.24.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000809; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.9.90.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000810; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000811; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000812; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000813; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000814; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000815; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100000816; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000817; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000818; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000819; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000820; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000821; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000822; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000823; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000824; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000825; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000826; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.12.117.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000827; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.4.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000828; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000829; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000830; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.9.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000831; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.124.7.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000832; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.221.242.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100000833; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.240.84.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000834; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.11.92.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100000835; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.131.226.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000836; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.229.64.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000837; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.54.82.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000838; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.86.99.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000839; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.124.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000840; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.142.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000841; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.150.174.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000842; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.165.122.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000843; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.0.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000844; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000845; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100000846; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000847; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000848; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000849; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000850; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100000851; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000852; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000853; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000854; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000855; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000856; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100000857; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000858; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000859; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000860; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000861; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000862; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000863; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000864; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000865; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000866; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100000867; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000868; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000869; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000870; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000871; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000872; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000873; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000874; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000875; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000876; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000877; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000878; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000879; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000880; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000881; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000882; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000883; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000884; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000885; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000886; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000887; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000888; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000889; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000890; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000891; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000892; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000893; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000894; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000895; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000896; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000897; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000898; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000899; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000900; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000901; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000902; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000903; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000904; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000905; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000906; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000907; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000908; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000909; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000910; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000911; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000912; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000913; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000914; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000915; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000916; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000917; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000918; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000919; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000920; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000921; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000922; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000923; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000924; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000925; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000926; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000927; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000928; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100000929; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000930; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100000931; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000932; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000933; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000934; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000935; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000936; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000937; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000938; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000939; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000940; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000941; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000942; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000943; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000944; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000945; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000946; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000947; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000948; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000949; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000950; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000951; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000952; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000953; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000954; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000955; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000956; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000957; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000958; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000959; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000960; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000961; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000962; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000963; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000964; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000965; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000966; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000967; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000968; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000969; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100000970; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000971; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000972; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000973; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000974; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000975; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000976; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000977; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000978; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000979; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000980; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000981; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000982; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000983; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000984; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000985; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000986; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000987; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000988; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000989; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000990; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000991; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000992; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000993; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000994; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000995; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000996; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000997; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000998; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000999; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001000; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100001001; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001002; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001003; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001004; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001005; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001006; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001007; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001008; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001009; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001010; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001011; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001012; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001013; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001014; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001015; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001016; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001017; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001018; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001019; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001020; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001021; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001022; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001023; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001024; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001025; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001026; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001027; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001028; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001029; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001030; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001031; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001032; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001033; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001034; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001035; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001036; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001037; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001038; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001039; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001040; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001041; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001042; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001043; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001044; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001045; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001046; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001047; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001048; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001049; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001050; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001051; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001052; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001053; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001054; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001055; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001056; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001057; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001058; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001059; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001060; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001061; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001062; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001063; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001064; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001065; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001066; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001067; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001068; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001069; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001070; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001071; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001072; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001073; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001074; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001075; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001076; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001077; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001078; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001079; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001080; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001081; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001082; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001083; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001084; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001085; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001086; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001087; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001088; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001089; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001090; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001091; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001092; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001093; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001094; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.73.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001095; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001096; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001097; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001098; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001099; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001100; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001101; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001102; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001103; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001104; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001105; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001106; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001107; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001108; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001109; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001110; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001111; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001112; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001113; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001114; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001115; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001116; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001117; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001118; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001119; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001120; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001121; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001122; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001123; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001124; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001125; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001126; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001127; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001128; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001129; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001130; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001131; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001132; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001133; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001134; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001135; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001136; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001137; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001138; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001139; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001140; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001141; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001142; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.19.183.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001143; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.205.101.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001144; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.21.164.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001145; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.217.8.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001146; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.22.117.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001147; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.222.252.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001148; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.34.183.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001149; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.48.235.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001150; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.72.91.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001151; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.95.136.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001152; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.159.58.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001153; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.60.84.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001154; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.99.210.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001155; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.114.60.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001156; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.116.203.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001157; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.122.13.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001158; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.123.208.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001159; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.125.44.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001160; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.157.66.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001161; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.175.236.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001162; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.105.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001163; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.110.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001164; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.165.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001165; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.214.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001166; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.34.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001167; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.96.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001168; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.104.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001169; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.180.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001170; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.242.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001171; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.218.5.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001172; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.248.80.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001173; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.111.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001174; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.53.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001175; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.94.170.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001176; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.138.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001177; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.218.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001178; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.218.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001179; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.143.60.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001180; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.193.107.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001181; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001182; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001183; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.210.45.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001184; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.215.47.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001185; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.224.242.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001186; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.236.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001187; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.59.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001188; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.113.209.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001189; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.108.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001190; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.43.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001191; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.60.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001192; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.61.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001193; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.99.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001194; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.43.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001195; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.43.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001196; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.120.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001197; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.164.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001198; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.200.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001199; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.202.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001200; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001201; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001202; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.127.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001203; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.123.205.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001204; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.123.211.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001205; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.138.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001206; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.121.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001207; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.152.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001208; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.160.98.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001209; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.233.0.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001210; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.235.252.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001211; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.53.197.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001212; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.105.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001213; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.105.225.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001214; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.109.169.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001215; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.128.152.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001216; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.144.9.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001217; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.185.112.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001218; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.18.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001219; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.29.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001220; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.92.207.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001221; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.164.185.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001222; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.175.115.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001223; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.74.149.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001224; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.106.209.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001225; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.107.3.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001226; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.117.2.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001227; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.172.110.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001228; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.174.101.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001229; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.181.10.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001230; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001231; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001232; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001233; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001234; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.221.3.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001235; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.222.58.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001236; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.228.141.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001237; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.233.186.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001238; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.26.113.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001239; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.34.16.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001240; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.43.19.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001241; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.55.1.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001242; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.68.230.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001243; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.81.157.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001244; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001245; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001246; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001247; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001248; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001249; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001250; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.151.144.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001251; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.219.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001252; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001253; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001254; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001255; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.253.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001256; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.225.120.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001257; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.232.44.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001258; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.28.60.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001259; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.34.4.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001260; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.73.188.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001261; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.12.10.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001262; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.188.124.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001263; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.212.200.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001264; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.85.244.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001265; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.21.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001266; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.231.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001267; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.113.81.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001268; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.13.179.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001269; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.138.200.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001270; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.143.220.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001271; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.152.41.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001272; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.178.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001273; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.242.242.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001274; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.81.100.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001275; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.83.202.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001276; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"189.222.157.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001277; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.0.42.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001278; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.109.178.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001279; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.110.161.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001280; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.111.151.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001281; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.119.207.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001282; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.12.99.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001283; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001284; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001285; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001286; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001287; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001288; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.15.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001289; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.20.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001290; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.147.16.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001291; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.159.240.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001292; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.187.55.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001293; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.210.214.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001294; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.177.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001295; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.226.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001296; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.49.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001297; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.214.24.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001298; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.216.140.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001299; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.65.206.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001300; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.73.12.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001301; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.92.4.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001302; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001303; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001304; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.41.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001305; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"191.254.225.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001306; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"191.255.248.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001307; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.153.57.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001308; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.210.175.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001309; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.185.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001310; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.209.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001311; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.220.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001312; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.223.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001313; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.228.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001314; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.230.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001315; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.3.152.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001316; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.3.73.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001317; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.99.240.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001318; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.142.146.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001319; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.228.135.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001320; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.113.107.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001321; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.147.142.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001322; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.15.36.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001323; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.15.36.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001324; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.152.35.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001325; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.38.20.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001326; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.139.126.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001327; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.162.70.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001328; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.228.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001329; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.24.94.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001330; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.202.26.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001331; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.218.48.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001332; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.166.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001333; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.50.27.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001334; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.133.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001335; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.174.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001336; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.207.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001337; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.213.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001338; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.251.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001339; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.251.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001340; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.46.132.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001341; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.46.201.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001342; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"199.188.101.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001343; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1am.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100001344; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.229.89.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001345; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.239.22.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001346; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.249.161.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001347; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.37.149.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001348; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.37.203.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001349; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001350; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.125.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001351; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.92.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001352; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.57.122.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001353; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.83.152.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001354; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"20.185.42.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001355; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.104.150.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001356; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.105.167.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001357; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.111.189.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001358; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.194.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001359; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.2.161.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001360; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.30.132.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001361; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.142.147.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001362; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.170.46.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001363; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.184.163.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001364; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.187.102.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001365; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.200.254.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001366; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.203.27.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001367; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.205.12.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001368; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.107.233.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001369; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.150.176.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100001370; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.166.217.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001371; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.175.103.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001372; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.29.95.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001373; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.4.124.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001374; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.176.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001375; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.191.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001376; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.74.236.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001377; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.109.201.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001378; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.170.123.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001379; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.204.232.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001380; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.229.21.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001381; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.236.190.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001382; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.238.86.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001383; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.243.142.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001384; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.70.166.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001385; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.77.80.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001386; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.119.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001387; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.171.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001388; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.82.36.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001389; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.93.6.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001390; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"204.195.116.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001391; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"205.185.115.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001392; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"205.185.116.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001393; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"205.185.123.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001394; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.248.137.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001395; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.47.41.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001396; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.180.228.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001397; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.5.32.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001398; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.163.58.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001399; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.75.27.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001400; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.39.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001401; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001402; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001403; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.46.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001404; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.124.149.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001405; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.152.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001406; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.153.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001407; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.234.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001408; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.237.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001409; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.245.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001410; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.68.242.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001411; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.96.116.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001412; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.116.220.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001413; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.132.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001414; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.75.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001415; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.200.160.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001416; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.204.215.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001417; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.66.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001418; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.93.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001419; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.216.66.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001420; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.114.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001421; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.120.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001422; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.246.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001423; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.238.83.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001424; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.247.113.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001425; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.247.5.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001426; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.32.122.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001427; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.122.86.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001428; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.143.227.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001429; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.156.215.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001430; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.46.197.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001431; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.56.197.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001432; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.8.251.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001433; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.123.206.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001434; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.135.178.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001435; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.14.173.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001436; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.149.182.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001437; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.149.190.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001438; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001439; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001440; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001441; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001442; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001443; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001444; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.114.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001445; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001446; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001447; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001448; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001449; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001450; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001451; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.117.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001452; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001453; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001454; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.119.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001455; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001456; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001457; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001458; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001459; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.189.178.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001460; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.240.218.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001461; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.249.156.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001462; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.27.8.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001463; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.254.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001464; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.255.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001465; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.255.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001466; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.127.185.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001467; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.158.238.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001468; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.170.240.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001469; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.183.54.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001470; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.36.12.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001471; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"217.11.75.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001472; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.12.181.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001473; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.2.40.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001474; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.234.165.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001475; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.238.246.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001476; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.28.160.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001477; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.207.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001478; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.227.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001479; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.68.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001480; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.81.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001481; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.56.93.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001482; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.58.92.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001483; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.59.116.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001484; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.72.207.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001485; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.79.103.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001486; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.93.102.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001487; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.93.102.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001488; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.102.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001489; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.11.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001490; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.12.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001491; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.26.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001492; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.29.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001493; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.186.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001494; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.139.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001495; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.150.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001496; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.214.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001497; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.50.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001498; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.241.6.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001499; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.1.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001500; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.1.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001501; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.163.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001502; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.171.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001503; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.245.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001504; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.5.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001505; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.69.71.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001506; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.80.217.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001507; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.85.145.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001508; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"21robo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100001509; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.118.168.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001510; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.126.237.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001511; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.200.22.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001512; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.247.91.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001513; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.71.239.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001514; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.90.159.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001515; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.1.144.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001516; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.124.78.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001517; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.113.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001518; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.157.191.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001519; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.136.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001520; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.202.232.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001521; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.130.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001522; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.251.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001523; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.116.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001524; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.172.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001525; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.184.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001526; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.252.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001527; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.8.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001528; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.232.1.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001529; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.235.137.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001530; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.112.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001531; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.32.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001532; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.34.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001533; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.43.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001534; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.68.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001535; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.108.17.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001536; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.118.248.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001537; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.119.65.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001538; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.132.125.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001539; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.103.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001540; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.67.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001541; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.9.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001542; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.148.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001543; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.211.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001544; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.17.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001545; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.237.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001546; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.17.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001547; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.162.187.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001548; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.179.215.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001549; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.185.116.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001550; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.187.9.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001551; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.211.72.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001552; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.236.85.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001553; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.238.230.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001554; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.239.83.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001555; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.248.64.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001556; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.92.9.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100001557; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.95.190.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001558; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.99.171.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001559; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.131.201.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001560; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.166.117.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001561; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.167.118.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001562; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.225.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001563; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.234.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001564; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.5.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001565; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.73.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001566; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.115.118.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001567; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.125.186.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001568; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.126.120.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001569; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.228.143.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001570; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.24.213.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001571; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.149.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001572; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.21.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001573; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.95.89.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001574; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.103.74.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001575; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.11.141.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001576; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.119.158.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001577; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.137.147.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001578; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.137.233.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001579; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.152.235.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001580; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.158.25.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001581; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.176.206.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001582; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.184.1.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001583; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.192.191.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001584; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.225.114.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001585; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.227.190.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001586; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.35.245.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001587; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.39.181.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001588; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.39.34.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001589; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.42.229.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001590; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.45.4.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001591; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.51.91.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001592; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.53.163.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001593; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.53.163.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001594; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.89.140.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001595; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.1.245.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001596; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.1.245.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001597; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.105.106.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001598; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.105.152.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001599; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.116.84.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001600; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.14.81.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001601; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.141.218.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001602; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.147.29.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001603; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.147.40.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001604; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.184.251.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001605; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.193.196.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001606; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.193.217.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001607; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.149.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001608; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.159.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001609; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.192.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001610; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.210.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001611; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.22.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001612; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.23.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001613; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.232.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001614; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.3.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001615; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.34.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001616; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.110.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001617; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.140.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001618; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.32.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001619; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.201.183.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001620; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.202.182.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001621; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.102.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001622; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.116.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001623; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.154.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001624; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.165.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001625; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.185.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001626; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.213.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001627; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.255.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001628; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.28.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001629; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.4.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001630; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.68.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001631; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.7.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001632; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.87.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001633; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.94.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001634; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.204.253.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001635; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.205.178.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001636; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.136.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001637; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.154.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001638; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.80.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001639; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.151.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100001640; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.155.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001641; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.170.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001642; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.119.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001643; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.152.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001644; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.160.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001645; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.164.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001646; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.237.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001647; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.247.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001648; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.25.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001649; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.34.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001650; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.92.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001651; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.208.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001652; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.231.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001653; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.107.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001654; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.172.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001655; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.234.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001656; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.236.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001657; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.44.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001658; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.63.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001659; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.104.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001660; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.109.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001661; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.175.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001662; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.255.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001663; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.66.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001664; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.84.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001665; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.214.37.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001666; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.139.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001667; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.190.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001668; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.212.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001669; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.253.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001670; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.34.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001671; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.71.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001672; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.98.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001673; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.128.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001674; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.131.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001675; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.144.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001676; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.197.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001677; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.225.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001678; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.227.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001679; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.234.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001680; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.133.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001681; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.191.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001682; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.248.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001683; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.132.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001684; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.151.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001685; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.160.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001686; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.176.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001687; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.192.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001688; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.83.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001689; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.20.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001690; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.249.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001691; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.85.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001692; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.221.239.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001693; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.241.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001694; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.249.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001695; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.76.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001696; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.223.242.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001697; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.24.28.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001698; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.129.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001699; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.154.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001700; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.16.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001701; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.2.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001702; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.212.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001703; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.58.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001704; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.237.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001705; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.43.117.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001706; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.0.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001707; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.11.51.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001708; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.13.23.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001709; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.124.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001710; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.179.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001711; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.184.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001712; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.191.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001713; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.194.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001714; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.216.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001715; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.219.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001716; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.24.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001717; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.30.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001718; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.63.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001719; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.65.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001720; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.79.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001721; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.94.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001722; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.179.201.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001723; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.195.84.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001724; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001725; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001726; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.28.7.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001727; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.30.119.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001728; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32.208.157.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001729; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32792.prolocksmithwinterpark.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100001730; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"35.184.169.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001731; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.107.209.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001732; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.108.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001733; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.248.228.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001734; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.250.203.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001735; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.157.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001736; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.18.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001737; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.51.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001738; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.255.90.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001739; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.33.160.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001740; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.34.150.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001741; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.105.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001742; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.111.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001743; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.139.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001744; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.89.18.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001745; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360.lcy2zzx.pw"; content:"Host"; http_header; classtype:trojan-activity; sid:100001746; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360down7.miiyun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100001747; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.222.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001748; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.233.60.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001749; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.179.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001750; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.180.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001751; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.44.238.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001752; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.49.230.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001753; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.14.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001754; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.14.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001755; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.230.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001756; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"38.77.14.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001757; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.245.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001758; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.98.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001759; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.117.31.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001760; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.162.104.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001761; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.196.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001762; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.59.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001763; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.66.44.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001764; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001765; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.125.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001766; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.146.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001767; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.148.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001768; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.206.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001769; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.124.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001770; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.171.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001771; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.249.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001772; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.60.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001773; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.167.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001774; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.67.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001775; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.10.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001776; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.163.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001777; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.168.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001778; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.203.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001779; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.237.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001780; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.132.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001781; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.194.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001782; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.235.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001783; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.33.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001784; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.78.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001785; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.113.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001786; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.114.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001787; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.14.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001788; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.150.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001789; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.197.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001790; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.209.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001791; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.48.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001792; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.63.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001793; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.94.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001794; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.163.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001795; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.166.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001796; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.218.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001797; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.91.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001798; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.93.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001799; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.127.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001800; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.18.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001801; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.191.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001802; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.205.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001803; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001804; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.36.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001805; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.37.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001806; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.251.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001807; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.27.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001808; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.29.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001809; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.70.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001810; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.83.94.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001811; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.115.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001812; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.85.54.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001813; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.85.54.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001814; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.129.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001815; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.170.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001816; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.211.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001817; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.234.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001818; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.63.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001819; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.93.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001820; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.155.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001821; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.233.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001822; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.67.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001823; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.108.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001824; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.145.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001825; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.146.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001826; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.146.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001827; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.63.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001828; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.90.86.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001829; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"40.88.2.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001830; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.139.209.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001831; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.165.130.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001832; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.190.63.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001833; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.193.192.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100001834; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.219.185.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001835; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.226.60.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001836; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.72.203.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001837; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001838; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001839; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001840; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001841; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.202.101.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001842; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.43.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001843; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.65.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001844; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.82.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001845; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.180.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001846; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.239.26.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001847; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.56.15.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001848; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.61.99.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001849; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.82.217.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001850; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.84.37.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001851; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.241.106.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001852; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.241.108.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001853; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.252.8.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001854; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.115.172.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001855; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.1.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001856; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.203.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001857; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.135.134.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001858; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001859; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.141.84.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001860; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001861; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001862; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001863; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001864; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001865; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001866; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001867; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001868; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001869; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001870; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.164.140.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001871; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.165.215.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001872; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001873; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001874; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001875; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.110.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001876; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.22.209.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001877; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.229.53.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001878; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.23.22.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001879; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.248.194.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001880; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.27.253.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001881; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.51.104.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001882; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.6.24.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001883; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.81.235.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001884; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.85.90.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001885; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.85.90.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001886; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.85.90.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001887; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.9.148.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001888; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.92.108.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001889; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.95.169.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001890; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.117.42.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001891; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.172.75.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001892; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.182.173.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001893; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.182.173.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001894; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.20.63.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001895; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.214.27.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001896; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.24.130.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001897; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.241.120.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001898; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.243.179.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001899; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.249.33.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001900; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.25.242.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001901; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.118.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001902; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.86.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001903; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.97.76.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001904; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.103.219.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001905; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.145.152.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001906; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.151.23.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001907; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.157.97.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001908; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.16.131.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001909; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.21.202.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001910; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.46.231.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001911; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.162.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001912; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.87.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001913; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.143.43.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001914; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.156.35.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001915; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.158.201.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001916; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.20.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001917; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.21.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001918; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.174.182.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001919; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.170.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001920; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.178.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001921; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.179.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001922; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.68.221.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001923; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.188.62.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001924; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.2.70.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001925; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.42.37.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001926; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.53.146.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001927; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.79.75.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001928; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.95.226.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001929; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.115.174.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001930; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.115.174.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001931; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.121.91.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001932; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.252.47.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001933; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"51.222.56.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001934; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.114.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001935; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.180.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001936; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.114.246.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001937; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.162.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001938; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.174.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001939; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.125.191.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001940; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.126.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001941; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.141.122.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001942; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.166.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001943; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.200.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001944; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.143.189.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001945; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.218.67.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001946; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.22.212.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001947; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.226.129.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001948; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.229.194.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001949; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.230.89.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001950; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.238.42.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001951; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.240.147.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001952; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.241.78.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001953; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.243.123.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001954; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.243.126.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001955; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.243.208.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001956; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.118.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001957; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.80.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001958; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.48.154.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001959; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001960; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001961; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.76.151.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001962; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.97.206.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001963; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.0.211.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001964; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.102.168.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001965; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.202.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001966; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.207.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001967; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.214.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001968; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.237.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001969; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.246.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001970; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.23.114.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001971; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.58.117.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001972; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.10.91.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001973; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.13.61.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001974; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.164.130.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001975; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.175.124.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001976; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.20.217.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001977; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.208.135.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001978; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.122.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001979; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.186.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001980; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.216.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001981; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.233.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001982; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.6.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001983; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.100.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001984; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.111.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001985; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.202.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001986; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.206.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001987; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.218.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001988; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.220.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001989; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.254.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001990; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.162.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001991; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.83.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001992; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.195.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001993; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.177.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001994; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.86.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001995; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.223.84.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001996; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.25.109.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001997; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.15.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001998; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.39.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001999; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.4.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100002000; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.51.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002001; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.60.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100002002; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002003; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.26.104.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002004; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.10.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002005; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.8.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100002006; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.99.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002007; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.164.96.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002008; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.171.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100002009; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.91.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002010; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.247.224.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002011; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.253.94.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002012; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.3.149.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002013; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.41.230.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002014; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.47.220.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002015; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.103.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002016; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.199.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100002017; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.207.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002018; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.30.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002019; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.9.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002020; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.9.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100002021; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.99.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002022; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.102.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100002023; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.117.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002024; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.220.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100002025; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.103.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002026; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.64.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002027; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.180.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002028; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.181.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002029; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.57.96.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002030; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.170.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100002031; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.73.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002032; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.61.218.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100002033; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.65.172.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002034; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.0.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002035; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.104.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002036; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.110.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100002037; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002038; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100002039; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.255.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100002040; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.45.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002041; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.98.144.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100002042; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.1.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002043; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.141.73.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002044; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.131.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002045; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002046; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.155.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002047; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.227.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002048; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.31.126.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002049; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.149.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002050; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.222.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002051; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.43.207.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100002052; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.90.165.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002053; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"63.245.122.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002054; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"64.233.154.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100002055; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.125.128.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100002056; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.21.58.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002057; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.26.155.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002058; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.35.61.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100002059; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.229.214.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002060; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.57.55.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002061; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.74.7.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100002062; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.97.181.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100002063; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.245.151.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002064; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.3.169.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002065; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.8.138.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100002066; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.83.49.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100002067; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.84.138.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100002068; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.148.103.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100002069; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.151.244.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002070; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.174.182.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002071; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.175.107.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002072; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.188.144.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100002073; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.204.88.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002074; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.106.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002075; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.119.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002076; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.78.33.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002077; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.115.37.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002078; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.120.237.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100002079; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.123.245.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100002080; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.124.231.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100002081; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.127.214.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100002082; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.146.232.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002083; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.165.173.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100002084; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.196.158.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002085; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.222.157.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002086; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.229.0.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100002087; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.63.73.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100002088; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.115.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002089; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.227.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002090; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.76.240.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100002091; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.115.31.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002092; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.118.240.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002093; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.167.10.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002094; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.236.190.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002095; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.25.5.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002096; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.93.129.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002097; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.127.148.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002098; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.146.190.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002099; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.204.63.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100002100; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.29.48.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002101; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.34.191.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002102; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.40.234.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002103; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.106.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002104; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.2.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002105; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.235.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002106; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.47.133.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002107; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.71.60.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002108; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.85.106.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100002109; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.17.22.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002110; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.186.139.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002111; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.180.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002112; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.200.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100002113; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.202.249.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002114; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.214.69.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002115; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.229.230.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002116; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.31.40.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002117; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.204.216.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100002118; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.70.164.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002119; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.101.1.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002120; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.108.224.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002121; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.194.117.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100002122; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.195.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100002123; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.199.84.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002124; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.64.139.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002125; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.75.165.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002126; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.127.141.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002127; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.82.36.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002128; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.83.102.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002129; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.99.213.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002130; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.170.11.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002131; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.178.22.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100002132; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.217.92.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002133; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.250.199.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100002134; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.254.129.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002135; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.84.134.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002136; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.95.12.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100002137; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.111.182.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002138; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.237.25.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002139; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.53.144.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002140; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.50.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002141; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.52.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002142; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.89.203.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002143; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77st.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002144; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.145.224.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002145; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.186.155.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002146; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.141.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002147; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.240.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002148; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.41.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002149; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.168.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002150; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.188.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002151; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.104.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002152; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.176.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002153; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.27.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002154; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.23.172.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002155; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.8.225.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002156; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.11.195.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002157; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.13.49.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002158; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.130.253.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002159; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.147.123.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002160; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.175.42.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002161; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.7.170.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002162; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.79.58.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100002163; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.8.70.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002164; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.9.88.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100002165; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.107.89.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002166; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.19.101.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002167; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.211.181.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002168; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.217.12.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002169; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.99.128.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002170; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.136.146.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002171; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.165.44.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002172; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.191.40.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002173; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.213.141.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002174; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.187.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100002175; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.195.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100002176; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.237.128.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002177; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.244.219.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002178; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.246.225.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002179; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.92.36.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002180; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.103.108.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100002181; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.135.196.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002182; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.212.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002183; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.85.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002184; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.207.61.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002185; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.209.250.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002186; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.211.156.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002187; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.59.31.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002188; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.110.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002189; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.53.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002190; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.138.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100002191; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.139.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100002192; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.154.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100002193; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.187.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002194; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.100.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002195; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.106.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002196; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.108.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002197; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.131.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100002198; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.19.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002199; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.197.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002200; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.215.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002201; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.232.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002202; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.234.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002203; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.246.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002204; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.28.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002205; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.4.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002206; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.55.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002207; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.73.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002208; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002209; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.165.237.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002210; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.147.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100002211; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.218.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002212; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.242.253.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002213; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.252.9.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002214; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.210.219.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002215; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.212.219.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002216; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.50.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002217; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.95.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002218; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.238.24.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002219; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.247.83.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002220; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.254.39.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002221; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.33.111.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002222; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.39.248.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002223; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.40.127.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002224; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.42.20.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002225; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002226; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.11.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100002227; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.123.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002228; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.135.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002229; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.180.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002230; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.224.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002231; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.241.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002232; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.214.149.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002233; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.64.181.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002234; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.64.203.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002235; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.74.215.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002236; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.130.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002237; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.195.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002238; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"86.35.43.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002239; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.172.19.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002240; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.61.89.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002241; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87du.vip"; content:"Host"; http_header; classtype:trojan-activity; sid:100002242; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.208.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002243; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.219.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100002244; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.225.222.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002245; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.247.96.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002246; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.136.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002247; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.51.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002248; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.249.244.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002249; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.204.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002250; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.226.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002251; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.240.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002252; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.254.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002253; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.122.183.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002254; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.136.197.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002255; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.22.152.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002256; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.29.213.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002257; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.85.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002258; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8poieq.bn.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002259; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"90.152.144.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002260; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.132.197.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002261; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.138.215.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002262; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.177.139.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002263; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.187.103.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002264; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.205.173.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002265; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.212.150.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002266; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.214.124.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002267; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.217.104.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100002268; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.233.112.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002269; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.239.168.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002270; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.92.16.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002271; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.98.4.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002272; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.114.191.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002273; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.241.78.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002274; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.27.246.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002275; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.83.62.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002276; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.85.18.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002277; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.159.169.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002278; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.21.224.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002279; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.39.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100002280; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.39.79.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002281; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.137.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002282; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.182.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100002283; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.206.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002284; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.57.43.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002285; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.73.99.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002286; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.136.69.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002287; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.143.53.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002288; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.154.17.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002289; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.200.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002290; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.224.83.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002291; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.53.120.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002292; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.85.0.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002293; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.132.129.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002294; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.154.20.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002295; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.158.19.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002296; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.113.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002297; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.113.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002298; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.201.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002299; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.60.146.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002300; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.66.196.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002301; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.9.120.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002302; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.9.81.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100002303; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.239.73.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002304; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.47.147.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002305; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.68.140.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002306; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.96.199.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100002307; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.0.210.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002308; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.113.239.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002309; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.116.72.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002310; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.128.147.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002311; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.178.242.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100002312; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.30.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002313; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.150.245.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002314; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.33.195.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002315; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aatreefelling.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002316; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abad.tv"; content:"Host"; http_header; classtype:trojan-activity; sid:100002317; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abcd.bg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002318; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abissnet.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002319; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aboveandbelow.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002320; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absoftechworld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002321; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absupplies.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002322; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abyssos.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002323; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"academyshademani.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002324; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acbick.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002325; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"accesslinksgroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002326; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aceeprc.com.aceeprc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002327; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acellr.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002328; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acteon.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002329; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"activecost.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002330; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"addahealingmusic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002331; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002332; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.memengers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002333; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.erapor.smk-alasror.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002334; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.gentbcn.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002335; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.grandoceanvilla.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002336; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admission.kmctartskuttippuram.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002337; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adventureexplorer.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002338; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aeropilates.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002339; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afnan-amc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002340; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afoninblog.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002341; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afrimedspecialist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002342; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agemn.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002343; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenciadigitalwdys.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002344; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenda.gmelloinformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002345; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agentt.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002346; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agile8studio.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002347; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aiecons.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002348; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimnaukri.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002349; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aiqtest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002350; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aitorocio.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002351; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajpharmaholding.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002352; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajstudiollc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002353; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"akdvidyalaya.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002354; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"al-wahd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002355; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alasdemariposas.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002356; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alberts.diamondrelationscrm.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100002357; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alemelektronik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002358; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alena1971.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002359; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alexdubai.com.aldiabsteel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002360; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alka.institute"; content:"Host"; http_header; classtype:trojan-activity; sid:100002361; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"allforcreative.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002362; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alltheway.travel"; content:"Host"; http_header; classtype:trojan-activity; sid:100002363; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alpaylar.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002364; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"am-concepts.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100002365; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amamontajes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002366; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarresdeamorymaestroshechiceros.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002367; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarteargentina.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002368; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amos524.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002369; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ams.alvinasschools.org.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100002370; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anadelgbt.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002371; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anantam.net.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002372; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreelapeyre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002373; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andremaraisbeleggings.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002374; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002375; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002376; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreshconcejal.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002377; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelazgheibld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002378; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelsdetour.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002379; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angloteste.bigprime.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002380; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anhung1102.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002381; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anurontv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002382; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anysbergbiltong.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002383; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apartamentoscitta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002384; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api-ms.cobainaja.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002385; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002386; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.quocbao.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002387; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apoolcondo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002388; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.adsensearticle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002389; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.explicitsurveys.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002390; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.prerana.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002391; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apps.saintsoporte.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002392; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aps-scribe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002393; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aps-sv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002394; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apsusa.aero"; content:"Host"; http_header; classtype:trojan-activity; sid:100002395; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"areyoulivingwell.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002396; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"artedibujoyarquitectura.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002397; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"arwenyapi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002398; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ask-regard.call-save.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002399; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atfile.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002400; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"athenacapsg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002401; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atlanticsteelprocessing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002402; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atlasconcreteworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002403; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"attach.66rpg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002404; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atteuqpotentialunlimited.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002405; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"augustair.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002406; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"avadhanagames.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002407; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayahuascasp.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002408; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayamallah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002409; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azmeasurement.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002410; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"b2b.toptanakaryakit.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002411; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"backgrounds.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002412; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"badeggdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002413; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"balealgodon.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002414; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ballina.andrewmaughan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002415; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bangkok-orchids.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002416; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bangladeshunbound.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002417; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bary.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002418; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bash.givemexyz.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002419; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002420; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bavhome.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002421; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bbia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002422; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcmt.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002423; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcrg.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002424; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bdnextrend.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002425; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bearcatpumps.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002426; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beautincollagen.rs"; content:"Host"; http_header; classtype:trojan-activity; sid:100002427; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bekape.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002428; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beor360.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002429; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bespokeweddings.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100002430; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bestcarenepal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002431; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betone.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002432; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beveragesmiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002433; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bhavaniengineering.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002434; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bigmikesupplies.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002435; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilbosaquet.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002436; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilhen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002437; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing.citywine.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002438; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing.rahitechnosoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002439; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"binoy.stalphonsamissionva.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002440; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"biometrico.gpotecnosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002441; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bioskey.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002442; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birdi.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002443; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birminghamlink.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002444; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bizztradingbot.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002445; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bl4n3.zadns.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002446; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.callensaxen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002447; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.cast.re"; content:"Host"; http_header; classtype:trojan-activity; sid:100002448; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.difusodesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002449; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.oyinblogs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002450; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.takbelit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002451; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bmlifestyle.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002452; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bnrnews.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002453; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"boatpecas.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002454; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bodenstein.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002455; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"booksearch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002456; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bophelocare.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002457; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bounces.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002458; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"boutiqueofferte.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002459; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bpo.correct.go.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100002460; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brandtrust.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002461; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"braunfinancial.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002462; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brendanquine.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002463; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brideofmessiah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002464; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightaffiliatesales.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002465; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightmega.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002466; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightstarshop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002467; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"browardinsurancemiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002468; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bt2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002469; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"btdapi.robotake.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002470; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buigiaphat.com.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002471; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bulkyfoodja.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002472; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bullseyemedia.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002473; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"busandvanrentalmalaysia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002474; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buscascolegios.diit.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002475; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"business.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002476; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"business2.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002477; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bydspa.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002478; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c.oooooooooo.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002479; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c0140529.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002480; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"caballo.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002481; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cacaoprojects.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002482; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"calgaryautorepairservice.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002483; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"callbury.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002484; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"camminachetipassa.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100002485; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"canadianwork.cc"; content:"Host"; http_header; classtype:trojan-activity; sid:100002486; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capitalgroup-kw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002487; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capoeiraventrelivre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002488; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cardilicores.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002489; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cashyinvestment.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002490; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"catchperch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002491; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"catchpoolshetlands.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002492; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cazyacustomfurniture.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002493; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cbn.hypervoizd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002494; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ccauthority.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002495; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cdaonline.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002496; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cec.asso.ac-amiens.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002497; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cecra.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002498; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cellas.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002499; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cendekiabinaaksara.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002500; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cfs5.tistory.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002501; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ch.rmu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100002502; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chance5.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002503; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"changematterscounselling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002504; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chardhamdodham.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002505; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"check.askwordpressguru.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002506; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chezalice.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002507; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"childselect.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002508; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002509; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002510; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cible-energy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002511; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cifeer.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002512; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cirugiadenarizbucaramanga.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002513; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citihits.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002514; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citssolutions.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002515; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citycapproperty.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002516; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cityglobalgospel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002517; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"civi.istmejia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002518; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cleanbydesignllc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002519; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cloud.fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002520; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cm-arquitetos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002521; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"codsambal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002522; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colempaques.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002523; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colinde.pricesne.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002524; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colorpak.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002525; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"community.reimclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002526; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"comosairdoburaco.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002527; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"competancy.indigoconsult.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002528; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"conceptimagine.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002529; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"config.cqhbkjzx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002530; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"connectcapital.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002531; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"constructoralyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002532; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"consulateins.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002533; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"contributeindustry.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002534; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"controleautomacao.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002535; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"copelandscapes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002536; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"coulsongraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002537; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"count.mail.163.com.impactmedfoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002538; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"covid19.cyberschool.or.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002539; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cpanel.shivay.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002540; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr-sq.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002541; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"craftech.nxtnet.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002542; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crearechile.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002543; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"creationskateboards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002544; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crecerco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002545; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crittersbythebay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002546; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crm.notariavieitoyvelamazan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002547; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crmfarko.manivelasst.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002548; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crmroche.manivelasst.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002549; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crscorretordeimoveis.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002550; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cse-engineer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002551; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"csnserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002552; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ctracknxt.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002553; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cubescargoexpress.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002554; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"curasoles.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002555; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"currantmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002556; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cwa.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002557; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyclomove.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002558; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cynkon.kairoscs.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002559; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"czsl.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002560; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d.powerofwish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002561; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d9.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002562; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"da.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002563; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dagiionline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002564; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"damagedessentialtelecommunications.testmail4.repl.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002565; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"danaevara.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002566; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dartoonpictures.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002567; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.cdevelop.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002568; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.over-blog-kiwi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002569; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datapolish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002570; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dating.khokhas.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002571; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datsom.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002572; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davethompson.me.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002573; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davidmcguinness.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002574; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dayspringdaisies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002575; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dd.qiyuea.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002576; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"de.gsearch.com.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002577; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"decifrar.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002578; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"deigratia2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002579; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dekovizyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002580; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo-cliente.mindcreative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002581; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo.glassforcars.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002582; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo.iiitindia.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002583; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo6.hiites.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002584; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dent-estet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002585; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dental.xiaoxiao.media"; content:"Host"; http_header; classtype:trojan-activity; sid:100002586; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dentalalliance.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100002587; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"desertlandtrd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002588; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"designerliving.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002589; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"desiringhands.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002590; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"despertaresi.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002591; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"destinymc.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002592; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"detorre.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002593; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.sebpo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002594; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.watch-store.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002595; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dezcom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002596; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfcf.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002597; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfsfcsfcdsfsdvcfsvcscv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002598; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"diamantenegro.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002599; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dienmayminhhung.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002600; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"digilib.dianhusada.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002601; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"digisails.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002602; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"disinfection-cleaning.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002603; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"djking.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002604; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.1003b.56a.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002605; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002606; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.installcdn-aws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002607; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.packetstormsecurity.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002608; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.rina-roleplay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002609; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dnn.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002610; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dns.cyberium.cc"; content:"Host"; http_header; classtype:trojan-activity; sid:100002611; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dockerupdate.anondns.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002612; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"docman.orientalservices.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002613; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dodsonimaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002614; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"doitunlimited.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002615; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dokan.blueberrytec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002616; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom-chel74.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002617; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom.daf.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002618; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"doncedyhall.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002619; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"donghobinhminh.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002620; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dongphuctop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002621; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"donwnloasecury.ath.cx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002622; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002623; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosman.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002624; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dovberger.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002625; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.pcclear.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002626; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.udashi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002627; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.webbora.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002628; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down1.arpun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002629; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.caihong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002630; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.doumaibiji.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002631; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.exrnybuf.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002632; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.kaobeitu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002633; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.pdf00.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002634; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.rising.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002635; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.skycn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002636; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.zjsyawqj.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002637; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dragonsknot.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002638; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drbaby.com.sa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002639; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dream.pics"; content:"Host"; http_header; classtype:trojan-activity; sid:100002640; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drgroup.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002641; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drools-moved.46999.n3.nabble.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002642; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drsha.innovativesolutions.mobi"; content:"Host"; http_header; classtype:trojan-activity; sid:100002643; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsdisplay.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002644; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsenterprize.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002645; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsspainting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002646; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"du-wizards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002647; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duanhaozhang.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002648; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duque.guantanameratravel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002649; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dutapp.wisolve.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002650; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duvalcharter.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002651; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dx.qqyewu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002652; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dzinestudio87.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002653; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-commerce.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002654; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002655; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eandgdesign.com.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100002656; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eastsheen-glaziers.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002657; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebruyatkin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002658; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"edu.saicraftsman.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002659; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eedo.ee"; content:"Host"; http_header; classtype:trojan-activity; sid:100002660; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"efficientegroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002661; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"elbauldenora.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002662; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"emaids.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002663; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"emaz.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002664; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"emlak.ygtsoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002665; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"en.baoend.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002666; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enc-tech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002667; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"endurotanzania.co.tz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002668; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ennovate.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002669; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enriquecendocomconsorcio.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002670; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"equimination.ee"; content:"Host"; http_header; classtype:trojan-activity; sid:100002671; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"erp.nanotechproautocare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002672; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"erp.zilymax.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002673; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"escola.probommar.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002674; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"esnconsultants.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002675; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"essentia.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002676; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eubanks7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002677; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"europeanzonexxi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002678; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"evidencemarketing.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100002679; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exilum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002680; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exitoalfaomega.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002681; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"extrovertoffers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002682; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"f1sol.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002683; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fahrzeugdrive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002684; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"familydentist.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100002685; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"faveraprojects.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002686; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002687; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"felicienne.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002688; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"files.martellexpress.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100002689; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"filmotainment.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002690; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"final.makkahkmcc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002691; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fineartgallerym.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002692; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fisconline.casa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002693; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fix-america-now.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002694; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fixauto.illumetechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002695; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fixturegovernment.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002696; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fkd.derpcity.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002697; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flexypay.dsquaregroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002698; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flintspin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002699; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flyingbuddhadesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002700; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fmjplastering.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002701; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fms.buladde.or.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002702; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"follower.instantcashback.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002703; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foothills.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002704; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"footweardirect.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002705; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"forum.mdb.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002706; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fotoobjetivo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002707; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foundationrepairhoustontx.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002708; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foxeps.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002709; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fraud.bpcbankingtech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002710; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freecnetdownload.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002711; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freisites.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002712; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ftp.n3twork30cm.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100002713; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fullelectronica.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002714; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"funletters.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002715; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fusionfiresolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002716; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"futbolpr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002717; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"futuregraphics.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002718; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"g.pinmonkey.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002719; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gametwogame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002720; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garciadogshow.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002721; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002722; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow4.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002723; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gastoudergonny.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002724; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gbbulls.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002725; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gcpc.co.id.chronoscurtain.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002726; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"generaldeviales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002727; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfmodd1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002728; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfold1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002729; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghettohub.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002730; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghislain.dartois.pagesperso-orange.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002731; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giadungg7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002732; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giddos.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002733; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"glowinmedia.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002734; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmsebpl.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002735; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmtransformationacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002736; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmvadmission.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002737; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnimelf.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002738; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnscrew.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002739; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gold.investforex.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002740; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcake.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002741; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002742; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002743; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"golden-memories-funerals.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002744; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldenasiacapital.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002745; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gorecycle.fahadjutt.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002746; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gpotecnosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002747; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gracejukes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002748; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"grovershospital.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002749; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupoinmare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002750; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gruposelt.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002751; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gruppodomus.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002752; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gs.monerorx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002753; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"guide-to-cell-phones.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002754; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gulfac-house.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002755; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gvpcdpgc.edu.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002756; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"habbotips.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002757; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hagebakken.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100002758; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hamptonpartyoffive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002759; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hashmati.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002760; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hassanproduct.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002761; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hchfug.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002762; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hd11315.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002763; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hdkamera2003.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002764; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hds.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002765; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"heavymaq.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002766; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hellogorgeous.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002767; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"help.hizuko.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002768; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"herchinfitout.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002769; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hhaward.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002770; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandroadcoc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002771; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandslasvegas.atakdev.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002772; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hindi.factsriver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002773; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hiptool.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002774; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitpe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002775; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitstation.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002776; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hmpmall.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002777; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoagietesting10.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002778; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoayeuthuong-my.sharepoint.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002779; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"holmesservices.mobiledevsite.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002780; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"homefindersolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002781; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hongluosi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002782; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hookedupboatclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002783; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hortizwp.eastus.cloudapp.azure.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002784; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostingparacolombia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002785; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostzaa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002786; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"houstonshutters.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100002787; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hr2019.vrcom7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002788; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hrnautica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002789; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hseda.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002790; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsmwebapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002791; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"htownbars.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002792; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hubtech.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002793; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"huellacero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002794; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hunggiang.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002795; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"husamiyahschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002796; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iabmixx2020.rayadigital.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100002797; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iam313.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002798; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iammdshanto.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002799; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"icon.shatangmu.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002800; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idilsoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002801; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idj.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100002802; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idvindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002803; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ieclb.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002804; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ikexpert.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002805; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ilrafrica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002806; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"images.jermiau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002807; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"imbueautoworx.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002808; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"in-tune2016.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002809; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incrediblepixels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002810; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incredicole.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002811; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"indrasbikaner.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002812; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infair.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002813; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infovator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002814; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"initialnetworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002815; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inodesthetotaldesigners.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002816; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inrajahmundry.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002817; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"insignificantfinecore.testmail4.repl.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002818; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"instantindialoan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002819; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"insupportofchildren.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002820; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intellectsmart.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002821; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intersel-idf.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002822; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intuitiveideas.com.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100002823; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inversiones.arrayanfinanciero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002824; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"invest.xpcorporative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002825; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"investinae.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002826; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ioabc.wif.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002827; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ipmes.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100002828; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iremart.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002829; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iris101.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002830; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iscamenabe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002831; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isiphephelocon.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002832; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iso-dubai.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002833; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"israrulhaq.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100002834; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isso.ps"; content:"Host"; http_header; classtype:trojan-activity; sid:100002835; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ist-security.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002836; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"it123.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002837; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"italiandirezione.casa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002838; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itc-demo.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002839; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itelsys.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100002840; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jacktech.jackindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002841; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jaishritours.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002842; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamiekaylive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002843; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamshed.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002844; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jansen-heesch.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002845; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jathra.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002846; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jay.diamondrelationscrm.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100002847; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jebs.net.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002848; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jeffdahlke.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002849; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jennwolfemtb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002850; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jhayesconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002851; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jiaoyuzixun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002852; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jing-da.com.tw"; content:"Host"; http_header; classtype:trojan-activity; sid:100002853; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jnanbharati.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002854; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jobs.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002855; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"joelbonissilver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002856; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"join.cl8movement.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002857; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"josegene.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002858; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jpwoodfordco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002859; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jumpmanualjacobhiller.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002860; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jupiter.toxsl.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002861; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"justinscott.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002862; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kadigital.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002863; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalawatihomes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002864; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalogirosfinance.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002865; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kaptaanchapal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002866; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"karer.by"; content:"Host"; http_header; classtype:trojan-activity; sid:100002867; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"katanvetov.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100002868; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kensingtondriving.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002869; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ketofitnessexpert.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002870; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kevinjewelry.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002871; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"keywatch.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002872; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kingssa.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002873; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kjcpromo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002874; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kleinendeli.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002875; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"korrectconceptservices.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002876; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"krisbadminton.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002877; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ktb.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002878; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kubatoglubaklava.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002879; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kumaralok.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002880; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kwanfromhongkong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002881; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kz.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002882; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lacasadelosalebrijes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002883; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ladylabonde.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002884; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lameguard.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002885; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laodongnhat.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002886; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laravel.pointersoftwares.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002887; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lasermobilesounds.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002888; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laura9630fr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002889; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lauratomismith.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002890; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lautarosanmiguel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002891; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lawforall.edu.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002892; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lawschoolideas.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002893; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lceventos.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002894; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ld.mediaget.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002895; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ldgcorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002896; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"learning.real-academy.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002897; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leasiacherise.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002898; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leczkregoslup.acelero.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002899; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"legend.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002900; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leluibuffet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002901; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lestesteux.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100002902; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"libantravel.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002903; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.arihantmbainstitute.ac.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002904; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.uib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002905; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lidoraggiodisole.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100002906; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lifebeam.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002907; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lindnerelektroanlagen.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002908; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"linkintec.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002909; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"liquidaz.casa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002910; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"livetrack.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002911; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsindian.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002912; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lm.stagingarea.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002913; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmaancha.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100002914; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002915; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.login2.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002916; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"location-voitures.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100002917; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.trezor.com.stockfootagesindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002918; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"logotypfabriken.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100002919; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotix.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002920; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotusanddragonfly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002921; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.definerisco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002922; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.difusodesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002923; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.quama.pe"; content:"Host"; http_header; classtype:trojan-activity; sid:100002924; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ltc.typoten.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002925; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luminouspneuma.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002926; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luxomodels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002927; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m-technics.kz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002928; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.estudiomoros.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002929; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.mobilelocalsales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002930; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"madicon.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002931; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"magianegramagiablancayamarres.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002932; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.bs-eiendomme.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002933; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.golimoapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002934; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.jeffsono.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002935; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maksi.feb.unib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002936; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malaya.tv"; content:"Host"; http_header; classtype:trojan-activity; sid:100002937; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malwarecoding.github.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100002938; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managed.oss-cn-beijing.aliyuncs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002939; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managemysalon.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002940; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manantialesdelnorte.uy"; content:"Host"; http_header; classtype:trojan-activity; sid:100002941; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mangalyaa.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002942; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manhtien.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002943; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marcapinyo.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002944; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mario-sunjic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002945; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariobrown.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002946; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariotessarollo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002947; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketinfosales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002948; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marksidfgs.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002949; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"masjidhabeebiyarazviya.mysunni.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002950; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mastersofclientretention.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002951; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"masterthedaybook.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002952; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"materialescantu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002953; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"matruchhaya.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002954; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxiquim.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002955; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxoprint.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002956; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxtox.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002957; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maybethescobar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002958; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbgrm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002959; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbjtimes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002960; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbsolutions.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100002961; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbx.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002962; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mdasa.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002963; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medevlb.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002964; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"media-server.skyinternet.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002965; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medianews.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100002966; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mediawaysnews.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002967; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medistaffconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002968; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meeweb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002969; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"megagynreformas.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002970; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"megamart.afnan-amc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002971; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mehainteriors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002972; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"melissaleiteestetica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002973; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mercabits.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002974; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"merkathink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002975; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mertlog.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002976; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"metaflip.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100002977; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"metalin-cr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002978; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mettaanand.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002979; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meuoculosnanet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002980; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mfevr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002981; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002982; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002983; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"micalle.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002984; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michaelphilip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002985; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michimal2.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002986; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microblading.mirliandias.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002987; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microcomm-group.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002988; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mingguanwms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002989; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"minuevavida.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002990; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mirror.mypage.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002991; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"misterson.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002992; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mixr.at"; content:"Host"; http_header; classtype:trojan-activity; sid:100002993; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mkontakt.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100002994; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mktf.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002995; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmdx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002996; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmogollon.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002997; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mncarteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002998; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobile.illumetechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002999; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modelhouseturkey.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003000; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modernmanna.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003001; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"monetization.business"; content:"Host"; http_header; classtype:trojan-activity; sid:100003002; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"moninediy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003003; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mopai.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100003004; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"moreirawag.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003005; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"motorcomunicacion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003006; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"msacontabil.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003007; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mtspsmjeli.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003008; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mumgee.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003009; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mundialdebienes.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003010; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mundotecnologiasolar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003011; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"musaffirtours.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003012; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"muzimbiti.xigubo.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003013; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mxpiqw.am.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003014; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mydatebook.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003015; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymlql.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003016; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myritz.vettickal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003017; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mysalons.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003018; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myscape.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003019; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mysura.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100003020; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"naeemacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003021; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"namnyak.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100003022; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nap.mgsservers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003023; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"narcissisto.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003024; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"narimohol.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003025; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"navayurveda.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003026; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nec-i.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003027; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nedkellymyanmar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003028; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nelitrianggraeni.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003029; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nerve.untergrund.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003030; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nettube.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003031; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"networkwheels.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003032; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neuroenergy.fahadjutt.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003033; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neuromedic.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003034; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newfuture.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003035; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newinfinitysynergy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003036; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newtreedesign.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003037; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newvisionopticallab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003038; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newxing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003039; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nextdigitalday.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003040; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ngdaycare.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003041; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nguyenkekhuyen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003042; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nhorangtreem.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003043; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nicolas.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003044; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nidhi.iexist.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003045; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nikanpolimer.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003046; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilehouse.co.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003047; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilinkeji.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003048; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nimboohomes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003049; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"njtiledesigncenter.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003050; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nobius.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003051; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocalnoodle.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003052; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nomadicbees.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003053; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nonnarina.ax"; content:"Host"; http_header; classtype:trojan-activity; sid:100003054; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"notamuzikaletleri.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003055; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ns1.the-widyantos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003056; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsb.org.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003057; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nurmarkaz.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003058; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nxtnet.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100003059; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nyasabigbullets.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003060; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nyeh2o.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003061; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oakleyandfriends.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003062; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"obseques-conseils.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003063; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oecteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003064; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohe.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100003065; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohsewgorgeous.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003066; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oknoplastik.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003067; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oleholeh.memangbeda.website"; content:"Host"; http_header; classtype:trojan-activity; sid:100003068; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003069; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaromatic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003070; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omega.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100003071; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oms.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003072; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omscoc.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003073; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedrive.listifyapp.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003074; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"online.creedglobal.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003075; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinestatis.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003076; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"open.warehousesaas.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003077; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"opentoronto.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003078; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"opolis.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100003079; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"optimus.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100003080; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"order.bizpeed.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003081; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orientgatewayltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003082; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orion445.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003083; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oserve.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003084; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ot.weenets.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003085; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"otolithenrichment.fahadjutt.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003086; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"outletdosaquecedores.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003087; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ozemag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003088; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p1.lingpao8.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003089; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p3.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003090; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p6.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003091; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pablobrothel.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003092; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacificgroup.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100003093; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacwebdesigns.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003094; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pagos.krayem.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003095; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"palbas.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003096; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"palochusvet.szm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003097; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pamperpartypros.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003098; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parallel.rockvideos.at"; content:"Host"; http_header; classtype:trojan-activity; sid:100003099; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parejasfelices.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003100; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parkhussion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003101; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"partharaj.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100003102; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"partsapp.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003103; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pastorpaulocosta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003104; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.51lg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003105; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003106; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch3.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003107; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paths.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003108; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patriotsupremehemp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003109; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paulmercier.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003110; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payerrealty.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003111; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payments.atifsiddiqui.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100003112; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pcsoori.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003113; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pd.oceaniarp.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003114; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pemdodo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003115; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perfumeriamontes.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100003116; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpus.onlineman7-jombang.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003117; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpustekim.untirta.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003118; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pestoclean.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003119; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"petercollie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003120; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"petroindia.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003121; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ph4s.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003122; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phasdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003123; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phenhuong.sanpham.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100003124; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phittc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003125; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"photo360.kubooking.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003126; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pink99.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003127; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pinkpaprika.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003128; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"plasfan.ind.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003129; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"platinumherbal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003130; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"playground2.grupoaliadasca.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003131; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pmglance.startwriteup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003132; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pointactionsg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003133; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pokojewewladyslawowie.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003134; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pole.com.vc"; content:"Host"; http_header; classtype:trojan-activity; sid:100003135; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pool.phxdir.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003136; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pooltablemoversdenver.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003137; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"portal.premiumpunch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003138; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"posmicrosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003139; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"poulman.panagiotopoulos-tours.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003140; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ppdb.smk-ciptaskill.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003141; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestasicash.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003142; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestigehomeautomation.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003143; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"preview2.behalen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003144; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prishaartcreations.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003145; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"production.sparshims.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003146; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"programaoperadoronline.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003147; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"project.exquitec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003148; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promotapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003149; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promotoradescomplica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003150; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promoversdubai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003151; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003152; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003153; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosoc.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003154; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosupport.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003155; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosyarmakassar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003156; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"provence.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003157; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prueba.danielluza.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003158; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pujashoppe.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003159; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punchdialogues.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003160; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punjabdevelopersassociation.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003161; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pvcprinting.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003162; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qadir.tickfa.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003163; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qatarglobalconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003164; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qmsled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003165; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"quartier-midi.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100003166; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"querocar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003167; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rachmat-assuhaimi.my.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003168; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"radioafifense.deploys.live"; content:"Host"; http_header; classtype:trojan-activity; sid:100003169; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rainbowisp.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003170; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rajeshtailang.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003171; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakeshkhatri.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003172; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"raodigitalmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003173; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"raquelhelena.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003174; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rarlabarchiver.ac"; content:"Host"; http_header; classtype:trojan-activity; sid:100003175; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rasadbar.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003176; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rashika.ascarvalho.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003177; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ratemyfenancialadvisor.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003178; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ravenproductionsltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003179; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rc.ixiaoyang.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003180; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rcmesilva.charbelsales.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003181; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reacredit.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003182; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"readymmade.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003183; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"recyclethesurplus.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003184; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"redbats.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003185; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"redchillicrackers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003186; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reifenquick.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003187; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"relaxindulge.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003188; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"renehavis.com.ua"; content:"Host"; http_header; classtype:trojan-activity; sid:100003189; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"repatriacioncolombia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003190; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"res.uf1.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003191; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reseller.digimitra.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003192; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reseller.itechbrasil.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003193; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"resuco.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003194; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rezkabum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003195; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rhema.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100003196; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"richancyber.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003197; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"richmondminerals.co.zm"; content:"Host"; http_header; classtype:trojan-activity; sid:100003198; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinaefoundation.org.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003199; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinkaisystem-ht.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003200; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"riverfox.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003201; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkcable.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003202; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkverify.securestudies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003203; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertmcardle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003204; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertsinclair.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003205; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"romanianpoints.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003206; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ronnietucker.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003207; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roomsvc.servegate.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003208; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roshnijewellery.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003209; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rsgym.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003210; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubazar.pro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003211; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubycityvietnam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003212; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruisgood.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003213; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruwadalkuwait.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003214; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rydchile.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003215; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.51shijuan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003216; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.thechinesemuslim.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003217; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sac2.11xii.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003218; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sacredscentsonline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003219; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sadmahfuneralservices.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003220; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safcol-colors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003221; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safehubsecurity.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003222; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safety.nanotechproautocare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003223; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sahathaikasetpan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003224; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sainzim.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003225; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"saisoftwareinc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003226; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"salecorner.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003227; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"salonsaifa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003228; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"samriddhijyotish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003229; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sandovalgraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003230; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"santyago.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003231; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sasystemsuk.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003232; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scaladevelopments.scaladevco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003233; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scarfaceindustries.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003234; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scglobal.co.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003235; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schalke04rss.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003236; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scheff.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003237; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schoolbustracker.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100003238; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sculetus.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003239; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-doc-reader.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003240; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"segalsmetals.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003241; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sellmyphonela.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003242; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"selltechtoday.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003243; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"senbiaojita.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003244; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sentierodelviandante.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100003245; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"serendibsourcing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003246; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sericaasia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003247; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003248; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003249; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sexologistpakistan.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003250; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgb.ac.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100003251; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgessy.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003252; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shaheentbfoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003253; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shahikhana.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003254; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shahu66.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003255; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharkrigs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003256; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharpelevators.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003257; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shembefoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003258; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shivakunwar.com.np"; content:"Host"; http_header; classtype:trojan-activity; sid:100003259; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shoblasaathitrust.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003260; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shooka-co.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003261; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shop.goldspot.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100003262; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shopsofe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003263; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shrinikelectrical.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003264; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sibernetix.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003265; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sige.brisainformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003266; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"signatureads.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003267; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siili.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003268; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simoneporzi.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100003269; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simorsint.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003270; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simplithy.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003271; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindicato1ucm.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003272; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindpol.tiejuris.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003273; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sinergidwireka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003274; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sipahielektrik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003275; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sistelligent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003276; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skare.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003277; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyflyfares.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003278; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyscan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003279; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarthouseforum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003280; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smartzedu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003281; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smokesolutionindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003282; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smritiphotography.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003283; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sobariko.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003284; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sobethuacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003285; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.110route.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003286; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.officelabo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003287; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"softanis.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003288; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sogecoenergy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003289; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sohs.conceptechs.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003290; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"solar.amazingtribe.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003291; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somcorbera.cat"; content:"Host"; http_header; classtype:trojan-activity; sid:100003292; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somir.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003293; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soralapps.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003294; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sota-france.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003295; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"space.proactint.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003296; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spaceframe.mobi.space-frame.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003297; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"special-key.cf"; content:"Host"; http_header; classtype:trojan-activity; sid:100003298; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spent.com.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003299; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spetsesyachtcharter.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003300; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spititourism.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003301; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spittinfire.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003302; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sports-net.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003303; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"src1.minibai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003304; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sreenivasapaintingworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003305; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sriglobalit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003306; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"srilankamovies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003307; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"srvmanos.no-ip.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003308; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ss.monita.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003309; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"st.devcodin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003310; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"staging.apparelpunch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003311; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"starcountry.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003312; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"static.3001.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003313; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stiau.iuc.ac"; content:"Host"; http_header; classtype:trojan-activity; sid:100003314; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sticker.jewsjuice.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003315; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stiepancasetia.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003316; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stlukesohag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003317; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"store.ericalgarin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003318; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stott-thompson.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003319; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"streetdemo.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003320; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"suboldesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003321; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sumerians.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003322; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunaryem.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003323; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunbrero.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003324; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunmarkholidays.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003325; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"supermercadostia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003326; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-4-free.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003327; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support.clz.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003328; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"supportit.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100003329; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sw.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003330; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweaty.dk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003331; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweet-diet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003332; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swiftlogisticseg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003333; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swwbia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003334; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"syracusecoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003335; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sytraders.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003336; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"t.honker.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003337; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"t.netcatkit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003338; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tacticohosting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003339; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tadoo.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003340; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tafsantoursandtravels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003341; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tajushariya.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003342; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tallyinvoicecustomization.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003343; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taltus.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003344; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tapalkoedacoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003345; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tarravalleyfoods.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003346; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taurus.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003347; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tavo.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003348; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taxicabsrilanka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003349; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tc.snpsresidential.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003350; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tcy.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003351; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tdsp.yngw518.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003352; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tech332.synology.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100003353; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"techgms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003354; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teduae.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003355; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teleargentina.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003356; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"telescopelms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003357; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tencoconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003358; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teneth.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003359; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tentandoserfitness.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003360; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tessrobins.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003361; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.adventser.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003362; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.letraele.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100003363; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.lubrico.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003364; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.typoten.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003365; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.wanepghana.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003366; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.asistencia247.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003367; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100003368; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.basis-web.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003369; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.marrenconstruction.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100003370; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.clickitsolutionsmw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003371; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.thinkingcorp.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003372; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testnew.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003373; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testuat.itmoregistry.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003374; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teteaffiche.stephanebillon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003375; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tewoerd.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003376; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"textile.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003377; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tharringtonsponsorship.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003378; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theatretalkies.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003379; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecleaningladiespdx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003380; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecreativecafe.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003381; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thedesertship.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003382; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thediasporianexperience.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003383; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefirmlawgroup.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003384; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefuturelife.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003385; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thehighlightinterior.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003386; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thekassia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003387; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"themansionkasauli.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003388; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theprofinn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003389; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thesummitpc.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003390; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theurbantutors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003391; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thientu.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003392; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thosewebbs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003393; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thriveink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003394; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tianangdep.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003395; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickfoods.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003396; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tienda.ventadigital.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003397; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"timamollo.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003398; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"timegonebuy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003399; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tksb.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003400; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tlcc.com.gt"; content:"Host"; http_header; classtype:trojan-activity; sid:100003401; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tntmedia.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003402; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"todoapp.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003403; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"todocontodo.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003404; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonydong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003405; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonystram.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003406; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonyzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003407; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tooba.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100003408; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tools.reimclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003409; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topcell9.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003410; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toplevel.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003411; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topmask.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003412; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"torresquinterocorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003413; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toyotacollege.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003414; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpef.lsoftdemo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003415; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpke.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003416; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"translaterjemah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003417; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"travelwithmanta.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003418; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trendyshoes.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003419; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trezors.io.mahlongwa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003420; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trimestre.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003421; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"triplonet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003422; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"troki.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003423; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tropics.codeleek.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003424; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trudelfavreau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003425; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsd.jxwan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003426; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tulli.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003427; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tupperware.michaelroberge.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003428; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"turanggaresources.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003429; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"txtdust.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003430; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uat.indianfilmzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003431; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ublretailerdemo.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003432; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uc-56.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003433; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uisusa.uisusa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003434; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ultimate-24.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003435; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"umwelt-kirchhof.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003436; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unicorpbrunei.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003437; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uniengrisb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003438; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unyazitelecom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003439; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"upcbpta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003440; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"urbantrapfest.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003441; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"usamyforever.azureedge.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003442; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"used-jeans.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003443; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"useformoney.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003444; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"usmadetshirts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003445; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uss.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003446; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uzzepay.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003447; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vanzare.cabanabrazi2.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003448; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vbcargo.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003449; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vcah.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003450; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vectarts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003451; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vegadelcasero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003452; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vendas.lidiacarmeli.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003453; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"veterinariadrpopui.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003454; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vfocus.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003455; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vienen.gblix.srv.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003456; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vilaart.rs"; content:"Host"; http_header; classtype:trojan-activity; sid:100003457; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villamarand.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003458; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villatera.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003459; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"violinstop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003460; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"virtuleverage.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003461; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visions.alnisamart.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003462; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visualhome.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003463; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vitoriamodaintima.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003464; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vivationdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003465; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"viveirodoiscorregos.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003466; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vksales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003467; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vocalterra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003468; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vokasi.ub.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003469; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vologroup.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003470; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"voteyouramerica.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003471; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vpinversiones.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003472; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vpts.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003473; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vstsample.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003474; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vtube.fadlymotivator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003475; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vvsskmodinationalschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003476; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003477; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepliberia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003478; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepniger.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003479; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.eng.ubu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003480; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.geetle.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100003481; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.geomegasoft.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003482; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.newinnovationtechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003483; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.smarts-works.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003484; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003485; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webgis.perumdasolo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003486; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmailwindstreamnetmessagesecureapp1rqr.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100003487; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webpresario.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003488; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"website-work.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003489; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weinsteincounseling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003490; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wfinance.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003491; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whcms.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003492; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whiteresponse.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003493; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wi522012.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003494; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wikalen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003495; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildnights.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003496; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildtrust.mediadevstaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003497; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"willow-nettica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003498; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wimbamusica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003499; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"windcomtechnologies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003500; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wishesconcierge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003501; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woezon.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100003502; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wolfgang-brodte.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003503; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wonderhawaii.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003504; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woodsytech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003505; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wordpress.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003506; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wozata.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003507; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wp.readhere.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003508; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wpdemo.101clients.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003509; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"writtendeer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003510; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ws5588.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003511; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wsdyrmtcntlfarmtwsvb.dns.army"; content:"Host"; http_header; classtype:trojan-activity; sid:100003512; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wyklej.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003513; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"x-iting.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003514; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"x2vn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003515; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xia.beihaixue.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003516; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xixaoclothing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003517; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xk.996is.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003518; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--80akinnkiib6h.xn--90ais"; content:"Host"; http_header; classtype:trojan-activity; sid:100003519; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--polimerbizmimarlk-rvc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003520; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ybom.urbanolab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003521; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yeichner.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003522; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ylfpremium.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003523; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yoast.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003524; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yourclub1.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003525; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yourtopdog.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003526; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"youtubetrainingacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003527; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yp.hnggzyjy.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003528; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yskadvisors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003529; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yummyyogaudaipur.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003530; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yzkzixun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003531; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zmedcoach.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003532; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003533; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zz.690tx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003534; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100003535; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/86.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100003536; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c64.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100003537; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; http_uri; nocase; content:"amumufree.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003538; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/files/proxyi.exe"; http_uri; nocase; content:"analogx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003539; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003540; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dvdfv/anjj/downloads/jami.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003541; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/johnhast/efve/downloads/versiumr.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003542; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/johnhast/efve/downloads/versiumrr.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003543; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/4.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003544; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/6.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003545; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/labesoftware/update/downloads/boost-fps.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003546; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/labesoftware/update/downloads/install_plugin_x64_x86.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003547; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/labesoftware/update/downloads/vpn_free.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003548; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/clr.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003549; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatev.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003550; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/work.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003551; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/component.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003552; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003553; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/regsvc.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003554; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/skygaming/updates/downloads/update.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003555; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/001.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003556; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1488.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003557; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1_cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003558; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003559; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1fc2d.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003560; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/26a5.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003561; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003562; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/abjects.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003563; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/attached.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003564; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/b7f2c.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003565; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/battletext.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003566; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003567; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003568; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003569; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_makros.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003570; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_silent.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003571; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_sup.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003572; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003573; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003574; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003575; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildss.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003576; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientnik.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003577; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientrevers.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003578; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dcrat.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003579; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003580; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003581; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003582; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hans.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003583; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hulu.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003584; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfive.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003585; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfour.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003586; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelone.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003587; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelthree.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003588; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/inteltwo.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003589; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003590; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/kleiman.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003591; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003592; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/notepadplus.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003593; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003594; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003595; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003596; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003597; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/putty.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003598; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/rockethcd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003599; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/scvhost900.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003600; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/sessionwin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003601; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/siliculose.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003602; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/statemobi.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003603; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003604; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003605; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stgedo.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003606; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/svcperf.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003607; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003608; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurjok.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003609; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurusbabac.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003610; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/telekiller.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003611; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateanddr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003612; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateandr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003613; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/vhajeja.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003614; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/word.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003615; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/www.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003616; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/xlsd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003617; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003618; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003619; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hmatrix/data/hack1226.exe"; http_uri; nocase; content:"cd.textfiles.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003620; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003621; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/816070119281131570/816070273254162442/all.txt"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003622; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/825372018244583454/826848185246023750/loaddd.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003623; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/825372018244583454/826848348342059008/zeppelin.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003624; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/825372018244583454/826848405258633277/build.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003625; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/826198252025675816/826537386485612574/china.png"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003626; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003627; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003628; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/razor/rzr-winner_intro.zip"; http_uri; nocase; content:"chiptune.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003629; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003630; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003631; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/meteoradminz/hidden-tear/zip/master"; http_uri; nocase; content:"codeload.github.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003632; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; http_uri; nocase; content:"colfincas.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003633; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/qz0h69.pdf"; http_uri; nocase; content:"deepfreedom.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003634; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ktcghnmcwws43wzscphukbfnwtuaxidx&revid=0b8z0b7_i5sirk2xrtehmstg0vxvit3b4n3lmbdrdrjrodndrpq"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003635; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; http_uri; nocase; content:"drive.google.com.it-barcelona.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003636; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003637; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=12khl-unz2np4q54b2jgpwlsh6cuz0pss"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003638; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=13sfskplrox3d7uantwjj_trs6ciwvqa1"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003639; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003640; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=152yoztzpbx_bbpxepfackfklg8c1eao6"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003641; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=15hcgek7odccdafzf-9gvibnlgkirj4uo"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003642; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003643; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=194lqzukzvt-jtdxmihcvhd0yk1sxoybk"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003644; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003645; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003646; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1br5iufkkmmfeipqo3ecviqykbcdgcnio"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003647; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003648; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1cos43rmscrescxk3u40qjuqbwr-pydsn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003649; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003650; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1dhoxtwbb2ycn8q06gi3p-ao_llldff0e"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003651; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1dnm3wtjf6ud5fv6zop9cvbr4rs2of1-n"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003652; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1dqin1sdd6rbah3sggzsxzeqgrkmhjnqm"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003653; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003654; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1fensc6gc0fww0gbevsrnwwnlajypzdvv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003655; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1htinwtfrw1wc3_ma8odztnq0qpnic2q6"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003656; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003657; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003658; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003659; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1jkov2g5s1xkcq4bfb3uvmd6inhadatrg"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003660; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1jnarxelz8gtbkg5pa_s0rc8kv3ejkepn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003661; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1kjcylye1dbmhystyyotz-3pagktkhlhq"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003662; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1lsv4sko083sywwjndgqnsh_6sgqodqtu"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003663; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1mwgdd3lxuuk-bnsrm1rpclom0cmx7wob"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003664; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003665; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003666; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1nmf6kty3xsoygjxjhb-bsafvlfy-0lt2"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003667; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003668; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1p5fvqkxzwoiu_uauzbmrxpklsetculad"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003669; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003670; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1q1dwckludrpqijtrpw14_60d5nu7n97t"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003671; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1r9f9irwhutxozsbp2h9erd_a7fa2pwko"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003672; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1s221a6wpx6i7nfrztnhh9priojtybuxq"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003673; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1sjvkrinuscxqmbkdeusxaezazbiagnv3"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003674; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1so1trfuzt5-giahetghfhmd-_ot3rq35"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003675; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003676; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003677; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1uowridpynurgqlgqjbtgramigo2a9v76"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003678; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003679; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003680; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vjq92eqivh01yxmal20whl2es3ld6nxb"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003681; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003682; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003683; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003684; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003685; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003686; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yqpuxjbnjokc5fjgt-8xzuybr97rtvg2"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003687; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ywkgalidldb32pio6ywmbyvdk7oar3yy"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003688; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003689; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003690; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/1zilg/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003691; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/qcgfmfvh/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003692; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/emclick.zip"; http_uri; nocase; content:"e-mudhra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003693; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003694; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003695; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/x/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003696; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003697; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003698; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003699; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003700; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; http_uri; nocase; content:"file.elecfans.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003701; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003702; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003703; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; http_uri; nocase; content:"gist.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003704; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; http_uri; nocase; content:"hqdecig.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003705; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/suy/"; http_uri; nocase; content:"hsecaravans.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003706; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/19/items/startup_20210219/startup.txt"; http_uri; nocase; content:"ia801802.us.archive.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003707; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/online-timer-kvhxz/ilxl/"; http_uri; nocase; content:"ie-best.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003708; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100003709; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100003710; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ebook/cs17.exe"; http_uri; nocase; content:"jcedu.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003711; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003712; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003713; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003714; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; http_uri; nocase; content:"karmakoincodes.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003715; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dg/etrac/nf4emwz/"; http_uri; nocase; content:"kotakwarna.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003716; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe"; http_uri; nocase; content:"ksh.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003717; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/down/affiliate/kuaizip_setup_10029.exe"; http_uri; nocase; content:"kuaizip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003718; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/linuxforensicscode.zip"; http_uri; nocase; content:"linuxforensicsbook.com.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003719; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/k/big5/1giof6/"; http_uri; nocase; content:"minpic.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003720; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; http_uri; nocase; content:"my.cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003721; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/aacenc.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003722; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/doxillionsetup.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003723; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/4/1/6/6/4166984/keygen.exe"; http_uri; nocase; content:"newyarlfm.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003724; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; http_uri; nocase; content:"nhipcauytevietnhat.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003725; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; http_uri; nocase; content:"note.youdao.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003726; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; http_uri; nocase; content:"oldschoolvalue.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003727; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003728; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003729; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21108&authkey=acq44gahejhwrag"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003730; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003731; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003732; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003733; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003734; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003735; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003736; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003737; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003738; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003739; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003740; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003741; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003742; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003743; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003744; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003745; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003746; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003747; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003748; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003749; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003750; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003751; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=032ce380af7ab389&resid=32ce380af7ab389!210&authkey=akcynbtc0h3ui7e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003752; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=032ce380af7ab389&resid=32ce380af7ab389%21210&authkey=akcynbtc0h3ui7e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003753; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003754; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003755; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003756; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003757; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003758; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003759; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d!184&authkey=ackbiiarirejcam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003760; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d%21184&authkey=ackbiiarirejcam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003761; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003762; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003763; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003764; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003765; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0!1667&authkey=an8otd7jzc7xgho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003766; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0%211667&authkey=an8otd7jzc7xgho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003767; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0da4ace18aa7d1e2&resid=da4ace18aa7d1e2%21131&authkey=adjn1y5pp4a10_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003768; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003769; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003770; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003771; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003772; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003773; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003774; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003775; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003776; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003777; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f!286&authkey=almwisomhv3c0zc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003778; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003779; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003780; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003781; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003782; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003783; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003784; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003785; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003786; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003787; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003788; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003789; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003790; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003791; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003792; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003793; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003794; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!140&authkey=apn44x6bxlzq3ac"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003795; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!151&authkey=aeuk7knodrpenek"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003796; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!153&authkey=ao6e8g0bzbp_idw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003797; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!154&authkey=ah4chedbotzpmtq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003798; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!156&authkey=ajnqscnmrdonpkg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003799; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003800; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003801; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003802; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003803; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003804; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21140&authkey=apn44x6bxlzq3ac"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003805; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21151&authkey=aeuk7knodrpenek"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003806; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21153&authkey=ao6e8g0bzbp_idw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003807; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21154&authkey=ah4chedbotzpmtq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003808; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21156&authkey=ajnqscnmrdonpkg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003809; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003810; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003811; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003812; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003813; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003814; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003815; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003816; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003817; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003818; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003819; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003820; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003821; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003822; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003823; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003824; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2968c371f5450503&resid=2968c371f5450503!122&authkey=aaqhhxbnwfwrz28"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003825; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2968c371f5450503&resid=2968c371f5450503%21122&authkey=aaqhhxbnwfwrz28"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003826; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003827; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003828; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003829; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003830; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003831; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003832; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003833; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003834; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003835; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003836; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003837; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003838; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003839; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003840; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003841; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003842; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003843; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003844; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003845; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003846; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1!223&authkey=aajr842bzum0yg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003847; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003848; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003849; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003850; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003851; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003852; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003853; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003854; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003855; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003856; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003857; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003858; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003859; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003860; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003861; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003862; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003863; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003864; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003865; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3ee68228c34c236d&resid=3ee68228c34c236d%21129&authkey=apll6hu3-xetzxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003866; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003867; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003868; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003869; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003870; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba!2203&authkey=ajvalmr5l8epwvm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003871; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba%212203&authkey=ajvalmr5l8epwvm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003872; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003873; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003874; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003875; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003876; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003877; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21141&authkey=aazwaw2xjms24o0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003878; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003879; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003880; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003881; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003882; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003883; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003884; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003885; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003886; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003887; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003888; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003889; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003890; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003891; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003892; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003893; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003894; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003895; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003896; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003897; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003898; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003899; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003900; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003901; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003902; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003903; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003904; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003905; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003906; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003907; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003908; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003909; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003910; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003911; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003912; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003913; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003914; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003915; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003916; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003917; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003918; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003919; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003920; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003921; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003922; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003923; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003924; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003925; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003926; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003927; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003928; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003929; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003930; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003931; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003932; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003933; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003934; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003935; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003936; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003937; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003938; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003939; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003940; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003941; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003942; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003943; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003944; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003945; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003946; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003947; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003948; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003949; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003950; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003951; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003952; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003953; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003954; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003955; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003956; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003957; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003958; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003959; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003960; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003961; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003962; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003963; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003964; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003965; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003966; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003967; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003968; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003969; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003970; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003971; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003972; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003973; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003974; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003975; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003976; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003977; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003978; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003979; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003980; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003981; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21198&authkey=akq4jrbjm6spd9m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003982; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!109&authkey=ap-okubj9bvtlc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003983; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21106&authkey=an9dhtmtufpis-m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003984; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21109&authkey=ap-okubj9bvtlc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003985; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003986; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003987; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003988; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003989; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003990; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003991; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003992; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003993; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003994; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2!517&authkey=akfewcyiwlwomyk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003995; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003996; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21517&authkey=akfewcyiwlwomyk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003997; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003998; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003999; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004000; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004001; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004002; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004003; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004004; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004005; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004006; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004007; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004008; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004009; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004010; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004011; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004012; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004013; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004014; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!301&authkey=abquzhtdjg5pryk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004015; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!302&authkey=al2_xstzqulnnqw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004016; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!305&authkey=an-uuhplpk2zp5u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004017; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21301&authkey=abquzhtdjg5pryk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004018; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21302&authkey=al2_xstzqulnnqw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004019; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21305&authkey=an-uuhplpk2zp5u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004020; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004021; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004022; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70d8fa75c83fbdbe&resid=70d8fa75c83fbdbe%21144&authkey=acw8wl1noncfp-4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004023; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004024; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004025; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004026; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004027; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004028; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004029; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004030; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!106&authkey=ahu5s4ttjvxbnxo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004031; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!107&authkey=abj3eccentbeaqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004032; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!108&authkey=amvcygo4prlgt4i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004033; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!110&authkey=ahzuehvk5nvzo90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004034; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21106&authkey=ahu5s4ttjvxbnxo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004035; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21107&authkey=abj3eccentbeaqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004036; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21108&authkey=amvcygo4prlgt4i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004037; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21110&authkey=ahzuehvk5nvzo90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004038; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004039; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004040; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004041; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004042; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004043; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004044; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004045; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125570&authkey=aejqgjglwurnb0a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004046; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004047; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004048; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004049; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004050; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004051; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004052; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004053; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004054; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004055; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004056; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004057; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004058; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004059; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004060; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004061; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21444&authkey=abzxvycu0ggtmg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004062; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004063; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004064; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004065; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004066; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004067; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004068; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004069; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004070; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004071; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004072; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004073; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=89360b4c7415c088&resid=89360b4c7415c088%21106&authkey=akfcfq3zq5oof2i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004074; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=89360b4c7415c088&resid=89360b4c7415c088%21108&authkey=amfbkmapqbvzpvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004075; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004076; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004077; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004078; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004079; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004080; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!254&authkey=ajt5wxegbvzbwqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004081; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!255&authkey=aaimhpp89qmcfhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004082; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33%21254&authkey=ajt5wxegbvzbwqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004083; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004084; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004085; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004086; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004087; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004088; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!112&authkey=af43qpcgl0t2f5o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004089; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004090; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004091; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004092; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004093; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004094; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004095; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004096; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004097; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!305&authkey=apgh_teb3673nek"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004098; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!306&authkey=aibymhcuhqnmrwo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004099; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004100; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004101; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004102; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004103; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004104; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004105; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004106; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21305&authkey=apgh_teb3673nek"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004107; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004108; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004109; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004110; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004111; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004112; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004113; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004114; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004115; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004116; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004117; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004118; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004119; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004120; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004121; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004122; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004123; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004124; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004125; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004126; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004127; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004128; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004129; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004130; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004131; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9fb622acb27482ef&resid=9fb622acb27482ef%211197&authkey=aeacibxy2zlyxro"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004132; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004133; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004134; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004135; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004136; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004137; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004138; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004139; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a31988151cf6813e&resid=a31988151cf6813e%21107&authkey=ab9lanzt1aj_0ws"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004140; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004141; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004142; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004143; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004144; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004145; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004146; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004147; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004148; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21256&authkey=aapnly5qifymcvw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004149; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004150; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004151; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004152; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004153; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004154; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004155; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004156; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004157; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004158; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004159; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818!129&authkey=aesewk3cf5vbrxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004160; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818%21129&authkey=aesewk3cf5vbrxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004161; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004162; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004163; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004164; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004165; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004166; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004167; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004168; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004169; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004170; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004171; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004172; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004173; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004174; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004175; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004176; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004177; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004178; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004179; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004180; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004181; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004182; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004183; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004184; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004185; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004186; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004187; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004188; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1047&authkey=aod6jbxyicq2v4g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004189; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211047&authkey=aod6jbxyicq2v4g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004190; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004191; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004192; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004193; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004194; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004195; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004196; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004197; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004198; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004199; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004200; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004201; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004202; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004203; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004204; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004205; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004206; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004207; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004208; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004209; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004210; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004211; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004212; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004213; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004214; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004215; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004216; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004217; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004218; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004219; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004220; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004221; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004222; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004223; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!362&authkey=alycl9izrvfl7oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004224; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21362&authkey=alycl9izrvfl7oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004225; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004226; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004227; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004228; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004229; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cda6c13b54bbe48c&resid=cda6c13b54bbe48c!44331&authkey=afohia-wo-alwiy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004230; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cda6c13b54bbe48c&resid=cda6c13b54bbe48c%2144331&authkey=afohia-wo-alwiy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004231; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004232; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004233; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004234; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004235; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004236; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004237; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004238; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004239; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004240; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004241; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004242; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d4d413b6e7cf7088&resid=d4d413b6e7cf7088%211271&authkey=akz65bxpgvdxjb8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004243; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004244; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004245; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004246; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004247; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004248; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004249; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004250; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004251; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004252; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004253; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004254; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004255; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004256; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004257; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004258; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2!1818&authkey=anh2wga7qmhbmuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004259; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2%211818&authkey=anh2wga7qmhbmuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004260; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004261; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004262; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004263; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004264; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004265; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004266; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2!107&authkey=af-bicrg1c6vgck"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004267; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2%21107&authkey=af-bicrg1c6vgck"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004268; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004269; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004270; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004271; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004272; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004273; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004274; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004275; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004276; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004277; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004278; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e627fc797baa3032&resid=e627fc797baa3032%212324&authkey=aa8i-r7ixmcraha"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004279; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004280; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004281; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004282; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004283; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004284; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8!148&authkey=agjcwq650c8wdbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004285; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8!150&authkey=ami5aqoinvosjle"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004286; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8%21148&authkey=agjcwq650c8wdbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004287; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8%21150&authkey=ami5aqoinvosjle"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004288; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004289; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004290; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004291; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004292; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004293; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004294; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004295; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004296; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ef7cc06ce7ffafb8&resid=ef7cc06ce7ffafb8%21108&authkey=anmpeqm9gm_zv9m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004297; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004298; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004299; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004300; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004301; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004302; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004303; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004304; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004305; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004306; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004307; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004308; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004309; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004310; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004311; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004312; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004313; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004314; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004315; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!226&authkey=adho6klfkjflaqk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004316; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!229&authkey=akvo12quxgcwnk8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004317; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!234&authkey=abhyu_zfy6bhwmu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004318; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004319; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21226&authkey=adho6klfkjflaqk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004320; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21234&authkey=abhyu_zfy6bhwmu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004321; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c!115&authkey=adbcrakskolznjq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004322; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c%21115&authkey=adbcrakskolznjq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004323; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c%21116&authkey=anenotuhbsni0zu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004324; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004325; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004326; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004327; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004328; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004329; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004330; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004331; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004332; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004333; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004334; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21848&authkey=ag1_e421v-t5r9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004335; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004336; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!198&authkey=amg468jpljbyyky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004337; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21198&authkey=amg468jpljbyyky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004338; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004339; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004340; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004341; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004342; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004343; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004344; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004345; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004346; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004347; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004348; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/r/a39ev"; http_uri; nocase; content:"paste.ee"; content:"Host"; http_header; classtype:trojan-activity; sid:100004349; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/r/oitkz"; http_uri; nocase; content:"paste.ee"; content:"Host"; http_header; classtype:trojan-activity; sid:100004350; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/77jhk0iw"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004351; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/89hkc7wb"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004352; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/yqvsvlvq"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004353; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/llc/mwcacs65xienqdp/"; http_uri; nocase; content:"pierreconsulting.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004354; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bayesian-forecasting-amj5e/s5hqmf6/"; http_uri; nocase; content:"pioneiraagronegocio.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004355; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skoda22.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004356; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004357; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; http_uri; nocase; content:"qjbutterflyevents.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004358; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dhlshipmentawb80326979402.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004359; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/maersk-bl+draft-copy-shipping-documents.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004360; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/po+for+april+shipment.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004361; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zenar.exe"; http_uri; nocase; content:"racisa.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004362; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004363; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004364; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004365; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004366; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004367; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004368; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/myqseeaccount/one/main/one.htm"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004369; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004370; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004371; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004372; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tennc/webshell/master/other/small_shell.txt"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004373; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; http_uri; nocase; content:"res.yeshen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004374; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/q05z91"; http_uri; nocase; content:"sendspace.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004375; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ey4lpx8rx.zip"; http_uri; nocase; content:"shribharatvatika.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004376; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004377; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004378; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004379; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004380; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004381; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004382; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004383; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004384; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004385; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004386; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/a-nurse-ss8d9/z/"; http_uri; nocase; content:"technologydistilled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004387; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/23.exe"; http_uri; nocase; content:"tsrv4.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100004388; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/crisanar/defis/jek_crackme1.7.zip"; http_uri; nocase; content:"users.skynet.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100004389; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/amowvegfrt9ja/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004390; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004391; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004392; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004393; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004394; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb%5efr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004395; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb^fr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004396; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004397; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/151_155/tidex_-_short_stuff.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004398; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/syria-files/attach/222/222051_instruction.zip"; http_uri; nocase; content:"wikileaks.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004399; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.223.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000160; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.225.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000161; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.235.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000162; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.249.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000163; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.4.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000164; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110fss.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100000165; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.41.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000166; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.88.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000167; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.119.245.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000168; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.125.67.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000169; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.165.21.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000170; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.166.236.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000171; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.167.151.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000172; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.85.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000173; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.86.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000174; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.172.57.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000175; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.182.235.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000176; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.171.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000177; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.177.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000178; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.23.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000179; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.230.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000180; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.27.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000181; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.49.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000182; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000183; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000184; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.104.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000185; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.104.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000186; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000187; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000188; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000189; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000190; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000191; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000192; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000193; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.61.52.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000194; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.108.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000195; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.133.222.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000196; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.147.92.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000197; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.159.108.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000198; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.163.200.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000199; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.124.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000200; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.210.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000201; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.96.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000202; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.187.91.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000203; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.214.127.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000204; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.187.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000205; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.236.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000206; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.239.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000207; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.43.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000208; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.118.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000209; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.202.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000210; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.67.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000211; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.180.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000212; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.79.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000213; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.79.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000214; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.178.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000215; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.188.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000216; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.230.168.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000217; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.218.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000218; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.235.149.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000219; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.235.188.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000220; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.171.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000221; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.141.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000222; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.144.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000223; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.197.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000224; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.209.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000225; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.75.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000226; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.143.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000227; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.17.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000228; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.190.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000229; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.227.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000230; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.39.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000231; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.73.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000232; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.240.216.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000233; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.152.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100000234; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.2.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000235; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.243.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000236; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.12.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000237; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.8.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000238; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.126.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000239; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.162.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000240; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.180.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000241; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.51.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000242; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.100.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000243; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.121.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000244; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.16.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000245; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.191.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000246; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.214.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000247; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.240.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000248; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.25.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000249; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.8.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000250; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.81.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000251; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.82.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000252; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000253; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.197.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000254; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.109.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000255; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.118.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000256; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.26.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000257; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.79.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000258; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.250.102.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000259; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.218.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000260; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.136.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000261; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.196.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000262; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.221.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000263; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.239.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000264; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.254.208.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000265; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.254.32.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000266; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.38.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000267; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.6.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000268; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.8.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000269; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.121.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000270; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000271; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000272; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000273; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000274; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000275; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000276; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000277; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000278; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000279; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000280; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000281; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000282; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000283; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000284; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000285; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000286; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000287; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000288; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000289; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000290; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000291; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000292; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000293; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000294; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000295; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000296; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000297; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.127.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000298; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000299; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000300; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.85.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000301; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.87.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000302; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.88.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000303; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000304; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000305; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000306; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000307; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000308; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000309; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000310; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000311; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000312; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000313; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000314; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000315; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000316; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000317; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000318; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000319; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000320; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000321; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000322; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000323; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000324; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000325; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000326; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.35.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000327; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.38.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000328; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000329; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000330; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000331; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000332; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000333; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000334; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.240.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000335; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.87.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000336; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.224.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000337; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.65.53.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000338; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.153.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000339; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000340; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000341; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000342; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000343; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000344; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.226.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000345; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.78.45.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000346; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.117.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000347; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.118.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000348; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.127.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000349; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.207.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000350; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.215.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000351; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.218.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000352; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.146.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000353; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.18.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100000354; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.224.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000355; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.93.29.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000356; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.11.95.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000357; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.144.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000358; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.122.238.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000359; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.161.58.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000360; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.161.78.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000361; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.172.250.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000362; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.195.163.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000363; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.226.42.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000364; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.194.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000365; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.35.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000366; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.211.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000367; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.254.169.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000368; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.128.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000369; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.133.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000370; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.154.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000371; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.191.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000372; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.61.204.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000373; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.89.43.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000374; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.90.26.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000375; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.111.242.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000376; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.199.253.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000377; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.200.154.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000378; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.224.203.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000379; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.226.100.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000380; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.228.205.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000381; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.229.165.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000382; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.235.115.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000383; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.30.54.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000384; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.79.172.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000385; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.165.216.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000386; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.201.38.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000387; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.42.47.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000388; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.21.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000389; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.125.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000390; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.18.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000391; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.153.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000392; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.60.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000393; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.131.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000394; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.133.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000395; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.144.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000396; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.159.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000397; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.132.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000398; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.165.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000399; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.255.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000400; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.118.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000401; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.69.102.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000402; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.73.3.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000403; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.92.174.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000404; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.124.219.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000405; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.132.151.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000406; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.206.164.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000407; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.211.100.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000408; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.212.132.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000409; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.212.142.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000410; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.166.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000411; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.196.50.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000412; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000413; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000414; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.210.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000415; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.220.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000416; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.236.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000417; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.243.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000418; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.247.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000419; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.200.76.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000420; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.66.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000421; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.69.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000422; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.10.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000423; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.15.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000424; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.248.63.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000425; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.113.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000426; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.195.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000427; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.53.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000428; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.86.105.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000429; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.104.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000430; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.157.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000431; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.7.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000432; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.32.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000433; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.5.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000434; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.72.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000435; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.12.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000436; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.128.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000437; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.208.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000438; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.209.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000439; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.214.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000440; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.88.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000441; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000442; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000443; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.221.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000444; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.63.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000445; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.65.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000446; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.42.125.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000447; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.43.180.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000448; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.125.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000449; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.50.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000450; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.58.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000451; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.83.79.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000452; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.91.24.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000453; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.91.41.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000454; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.179.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000455; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.183.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000456; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.239.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000457; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.108.161.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000458; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.112.185.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000459; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.119.63.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000460; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.14.143.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000461; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.147.213.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000462; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.163.93.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000463; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.18.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000464; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.107.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000465; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.163.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000466; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.174.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000467; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.197.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000468; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.241.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000469; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.27.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000470; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.68.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000471; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.170.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000472; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.97.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000473; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.26.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000474; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.177.147.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000475; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.248.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000476; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.170.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000477; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.43.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000478; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.75.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000479; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.18.38.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000480; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.106.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000481; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.108.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000482; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.108.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000483; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.33.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000484; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.119.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000485; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.124.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000486; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.182.97.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000487; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.183.115.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000488; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.14.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000489; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.172.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000490; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.195.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000491; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.245.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000492; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.137.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000493; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.227.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000494; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.150.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000495; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.187.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000496; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.215.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000497; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.240.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000498; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.204.30.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000499; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.250.129.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000500; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.105.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000501; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.14.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000502; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.131.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000503; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.140.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000504; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000505; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000506; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.144.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000507; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.148.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000508; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.155.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000509; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.175.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000510; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.195.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000511; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.206.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000512; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.232.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000513; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.132.113.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000514; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.15.69.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000515; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000516; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000517; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000518; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000519; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.207.39.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000520; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.25.204.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000521; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.0.255.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000522; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.12.153.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000523; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.142.222.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000524; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.150.213.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000525; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.151.248.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000526; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000527; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000528; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000529; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000530; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000531; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000532; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000533; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000534; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000535; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000536; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000537; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000538; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000539; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000540; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000541; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.127.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000542; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.99.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000543; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.210.89.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000544; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.43.33.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000545; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.66.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000546; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.93.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000547; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.8.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000548; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.7.75.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000549; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.173.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000550; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.114.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000551; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.96.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000552; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.121.44.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000553; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.122.71.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000554; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.123.53.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000555; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.127.155.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000556; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.141.11.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000557; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.15.142.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000558; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.159.22.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000559; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.170.234.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000560; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.185.31.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000561; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.190.36.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000562; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.20.104.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000563; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.225.11.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000564; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.23.57.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000565; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.230.171.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000566; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.231.103.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000567; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.237.226.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000568; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.239.15.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000569; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.24.116.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000570; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.254.43.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000571; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.254.76.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000572; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.98.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000573; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.88.99.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000574; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.100.150.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000575; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.159.178.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000576; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.160.147.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000577; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.176.44.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000578; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.188.86.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000579; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.66.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000580; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.72.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000581; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.79.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000582; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.37.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000583; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.41.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000584; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.29.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000585; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.33.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000586; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.0.240.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000587; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.54.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000588; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000589; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000590; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.170.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000591; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000592; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.19.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000593; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.200.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000594; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.238.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000595; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.128.133.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000596; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.129.84.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000597; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.208.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000598; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.27.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000599; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.37.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000600; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.131.186.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000601; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.132.219.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000602; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.125.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000603; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.98.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000604; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.134.14.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000605; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.134.50.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000606; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.199.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000607; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.248.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000608; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.153.80.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000609; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.116.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000610; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.236.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000611; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.94.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000612; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.156.136.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000613; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.68.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000614; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.8.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000615; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.183.121.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000616; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.191.164.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000617; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.191.62.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000618; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.101.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000619; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.194.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000620; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.149.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000621; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.53.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000622; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.235.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000623; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.35.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000624; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.52.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000625; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.60.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000626; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.112.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000627; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.184.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000628; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.98.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000629; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.212.29.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000630; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.213.225.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000631; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.130.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000632; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.152.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000633; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.116.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000634; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.184.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000635; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.235.226.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000636; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.103.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000637; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.181.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000638; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.79.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000639; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.148.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000640; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.184.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000641; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.28.217.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000642; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.5.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000643; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.119.108.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000644; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.221.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000645; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.76.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000646; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.130.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000647; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.104.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000648; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.151.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000649; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.203.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000650; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.24.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000651; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000652; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.54.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000653; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.132.110.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000654; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.135.34.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000655; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.136.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000656; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.236.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000657; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.160.126.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000658; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.65.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000659; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.72.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000660; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.165.123.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000661; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.187.111.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000662; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.199.56.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000663; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.230.174.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000664; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.254.251.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000665; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.5.92.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000666; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.6.0.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000667; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.67.89.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000668; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.7.254.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000669; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.80.46.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000670; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.91.135.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000671; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.91.237.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000672; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.93.94.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000673; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.128.28.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000674; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.142.93.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000675; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.191.113.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000676; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.1.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000677; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.73.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000678; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.75.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000679; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.215.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000680; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.53.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000681; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.79.200.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000682; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"128.116.133.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000683; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"130.255.159.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000684; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"134.195.139.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000685; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"135.148.36.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000686; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"138.99.204.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100000687; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.159.226.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000688; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.170.173.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000689; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.216.102.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000690; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.227.46.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000691; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.102.17.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000692; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.102.97.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000693; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.136.80.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000694; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000695; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.160.34.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000696; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.189.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000697; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.241.227.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100000698; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.37.222.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000699; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.45.127.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000700; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.25.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000701; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.98.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000702; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.55.29.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000703; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"141.105.65.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000704; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.11.216.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000705; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.177.56.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000706; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"146.71.79.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000707; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"148.69.108.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000708; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.20.176.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000709; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000710; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000711; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000712; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000713; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000714; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.3.124.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000715; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.3.85.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000716; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14karatvisions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100000717; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"150.116.207.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000718; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.177.163.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000719; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.33.230.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000720; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.234.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100000721; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.47.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000722; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.152.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000723; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.135.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000724; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"155.138.134.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100000725; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.101.165.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000726; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.174.213.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000727; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.51.125.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000728; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"159.224.74.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000729; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.194.28.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000730; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.209.98.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000731; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.53.206.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000732; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"165.90.16.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000733; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"170.81.238.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000734; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.113.36.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100000735; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.113.38.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000736; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.121.255.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000737; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.114.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000738; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.176.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000739; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.179.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000740; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.162.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000741; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.174.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000742; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.105.36.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000743; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.114.244.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000744; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000745; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000746; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.79.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000747; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.81.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000748; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.93.194.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000749; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.167.85.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000750; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.169.46.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000751; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.19.58.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000752; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.233.85.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000753; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.235.209.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000754; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.25.113.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000755; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.95.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000756; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.97.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000757; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.119.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000758; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.92.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100000759; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.106.33.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000760; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.48.181.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000761; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.61.3.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000762; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.73.246.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000763; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.81.78.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000764; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.83.73.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000765; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.10.147.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100000766; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.11.193.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000767; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.11.65.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000768; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.117.66.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000769; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.145.200.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100000770; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.169.13.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000771; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.201.104.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000772; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.208.230.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000773; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.42.46.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000774; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.9.24.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000775; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.9.90.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000776; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000777; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000778; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000779; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000780; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000781; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100000782; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000783; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000784; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000785; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000786; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000787; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000788; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000789; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000790; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000791; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.12.117.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000792; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.4.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000793; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000794; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000795; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.9.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000796; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.124.7.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000797; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.221.188.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000798; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.240.84.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000799; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.11.92.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100000800; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.131.226.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000801; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.229.64.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000802; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.54.82.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000803; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.86.99.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000804; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.124.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000805; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.142.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000806; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.150.174.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000807; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.151.143.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000808; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.165.122.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000809; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.0.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000810; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000811; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000812; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000813; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000814; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000815; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100000816; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000817; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000818; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000819; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000820; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000821; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000822; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100000823; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000824; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000825; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000826; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000827; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000828; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100000829; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000830; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000831; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000832; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000833; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000834; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000835; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000836; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000837; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000838; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000839; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000840; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000841; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000842; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000843; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000844; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000845; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000846; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000847; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000848; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000849; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000850; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000851; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000852; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000853; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000854; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000855; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000856; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000857; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000858; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000859; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000860; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000861; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000862; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000863; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000864; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000865; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000866; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000867; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000868; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000869; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000870; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000871; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000872; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000873; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000874; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000875; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000876; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000877; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000878; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000879; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000880; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000881; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000882; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000883; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100000884; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000885; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000886; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000887; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000888; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000889; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000890; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000891; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000892; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000893; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000894; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000895; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000896; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000897; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000898; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000899; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000900; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000901; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000902; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000903; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000904; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000905; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000906; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000907; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000908; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000909; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000910; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000911; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000912; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000913; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000914; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000915; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000916; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000917; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000918; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000919; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100000920; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000921; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000922; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000923; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000924; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000925; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000926; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000927; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000928; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000929; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000930; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000931; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000932; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000933; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000934; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000935; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000936; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000937; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000938; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000939; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000940; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000941; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000942; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000943; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000944; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000945; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000946; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000947; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000948; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000949; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000950; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000951; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000952; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000953; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000954; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000955; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000956; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000957; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000958; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000959; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000960; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000961; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000962; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000963; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000964; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000965; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000966; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100000967; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000968; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000969; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000970; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000971; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000972; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000973; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000974; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000975; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000976; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000977; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000978; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000979; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000980; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000981; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000982; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000983; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000984; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000985; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000986; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000987; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000988; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100000989; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000990; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000991; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000992; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000993; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000994; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000995; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000996; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000997; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000998; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000999; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001000; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001001; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001002; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001003; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001004; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001005; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001006; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001007; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001008; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001009; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001010; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001011; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001012; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001013; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001014; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001015; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001016; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001017; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001018; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001019; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001020; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001021; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001022; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001023; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001024; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001025; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001026; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001027; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001028; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001029; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001030; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001031; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001032; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001033; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001034; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001035; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001036; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001037; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001038; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001039; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001040; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001041; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001042; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001043; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001044; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001045; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001046; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001047; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001048; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001049; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001050; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001051; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001052; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001053; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001054; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001055; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001056; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001057; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001058; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001059; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001060; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001061; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001062; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001063; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001064; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001065; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001066; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001067; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001068; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001069; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001070; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001071; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001072; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001073; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001074; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001075; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.19.183.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001076; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.205.101.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001077; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.21.164.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001078; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.217.8.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001079; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.22.117.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001080; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.222.252.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001081; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.34.183.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001082; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.48.235.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001083; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.95.136.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001084; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.159.58.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001085; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.60.84.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001086; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.99.210.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001087; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.114.60.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001088; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.116.203.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001089; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.122.13.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001090; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.123.208.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001091; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.157.66.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001092; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.175.236.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001093; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.105.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001094; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.110.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001095; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.165.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001096; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.214.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001097; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.34.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001098; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.96.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001099; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.104.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001100; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.180.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001101; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.242.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001102; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.218.5.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001103; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.248.80.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001104; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.111.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001105; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.53.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001106; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.94.170.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001107; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.138.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001108; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.218.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001109; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.218.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001110; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.143.60.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001111; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.193.107.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001112; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001113; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001114; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.210.45.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001115; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.215.47.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001116; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.224.242.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001117; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.236.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001118; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.59.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001119; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.113.209.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001120; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.108.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001121; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.43.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001122; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.60.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001123; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.61.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001124; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.99.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001125; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.43.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001126; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.120.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001127; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.164.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001128; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.202.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001129; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001130; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001131; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.26.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001132; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.152.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001133; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.160.98.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001134; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.233.0.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001135; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.235.252.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001136; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.53.197.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001137; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.105.225.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001138; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.109.169.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001139; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.128.152.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001140; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.29.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001141; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.92.207.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001142; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.164.185.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001143; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.175.115.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001144; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.74.149.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001145; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.106.209.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001146; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.107.3.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001147; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.117.2.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001148; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.172.110.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001149; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.174.101.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001150; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.181.10.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001151; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001152; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001153; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001154; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001155; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.221.3.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001156; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.222.58.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001157; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.228.141.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001158; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.233.186.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001159; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.26.113.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001160; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.34.16.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001161; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.43.19.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001162; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.55.1.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001163; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.68.230.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001164; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.81.157.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001165; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001166; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001167; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001168; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001169; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001170; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.151.144.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001171; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.219.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001172; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001173; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001174; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001175; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.253.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001176; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.225.120.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001177; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.232.44.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001178; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.28.60.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001179; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.34.4.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001180; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.73.188.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001181; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.12.10.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001182; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.188.124.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001183; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.212.200.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001184; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.21.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001185; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.231.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001186; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.113.81.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001187; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.13.179.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001188; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.138.200.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001189; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.143.220.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001190; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.152.41.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001191; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.178.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001192; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.179.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001193; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.199.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001194; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.242.242.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001195; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.81.100.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001196; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.83.202.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001197; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"189.222.157.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001198; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.0.42.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001199; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.109.178.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001200; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.110.161.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001201; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.111.151.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001202; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.119.207.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001203; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.12.99.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001204; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001205; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001206; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001207; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001208; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001209; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.15.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001210; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.20.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001211; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.147.16.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001212; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.159.240.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001213; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.187.55.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001214; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.210.214.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001215; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.177.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001216; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.226.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001217; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.49.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001218; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.214.24.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001219; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.216.140.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001220; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.65.206.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001221; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.73.12.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001222; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.92.4.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001223; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001224; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001225; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.41.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001226; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"191.254.225.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001227; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"191.255.248.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001228; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.153.57.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001229; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.210.175.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001230; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.185.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001231; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.209.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001232; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.220.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001233; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.228.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001234; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.230.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001235; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.3.152.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001236; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.3.73.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001237; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.99.240.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001238; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.142.146.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001239; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.228.135.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001240; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.113.107.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001241; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.147.142.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001242; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.15.36.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001243; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.15.36.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001244; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.152.35.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001245; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.38.20.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001246; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.139.126.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001247; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.162.70.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001248; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.228.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001249; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.24.94.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001250; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.202.26.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001251; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.218.48.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001252; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.166.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001253; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.50.27.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001254; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.133.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001255; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.174.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001256; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.207.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001257; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.213.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001258; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.251.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001259; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.251.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001260; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.46.132.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001261; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.46.201.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001262; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"199.188.101.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001263; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1am.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100001264; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.229.89.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001265; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.239.22.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001266; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.37.149.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001267; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.37.203.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001268; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001269; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.125.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001270; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.92.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001271; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.57.122.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001272; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.83.152.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001273; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"20.185.42.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001274; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.105.167.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001275; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.111.189.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001276; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.194.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001277; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.2.161.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001278; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.30.132.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001279; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.142.147.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001280; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.170.46.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001281; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.184.163.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001282; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.187.102.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001283; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.200.254.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001284; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.203.221.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001285; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.203.27.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001286; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.107.233.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001287; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.150.176.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100001288; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.175.103.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001289; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.29.95.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001290; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.4.124.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001291; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.176.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001292; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.191.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001293; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.74.236.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001294; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.109.201.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001295; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.170.123.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001296; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.204.232.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001297; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.229.21.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001298; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.236.190.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001299; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.238.86.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001300; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.70.166.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001301; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.77.80.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001302; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.119.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001303; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.171.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001304; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.82.36.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001305; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.93.6.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001306; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"204.195.116.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001307; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"205.185.115.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001308; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"205.185.116.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001309; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.248.137.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001310; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.47.41.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001311; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.180.228.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001312; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.5.32.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001313; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.163.58.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001314; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.75.27.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001315; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.39.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001316; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001317; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001318; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.124.149.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001319; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.180.17.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001320; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.152.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001321; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.153.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001322; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.234.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001323; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.237.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001324; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.245.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001325; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.68.242.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001326; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.96.116.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001327; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.116.220.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001328; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.132.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001329; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.75.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001330; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.204.215.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001331; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.66.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001332; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.93.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001333; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.216.66.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001334; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.114.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001335; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.120.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001336; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.246.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001337; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.238.83.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001338; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.247.113.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001339; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.247.5.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001340; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.32.122.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001341; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.122.86.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001342; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.143.227.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001343; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.156.215.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001344; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.46.197.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001345; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.56.197.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001346; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.8.251.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001347; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.8.251.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001348; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.123.206.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001349; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.135.178.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001350; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.14.173.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001351; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.149.182.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001352; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.149.190.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001353; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001354; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001355; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001356; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001357; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001358; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.114.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001359; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.114.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001360; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001361; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001362; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001363; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001364; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001365; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.117.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001366; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001367; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001368; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001369; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.119.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001370; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001371; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001372; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001373; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.189.178.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001374; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.240.218.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001375; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.249.156.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001376; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.27.8.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001377; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.254.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001378; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.255.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001379; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.255.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001380; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.127.185.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001381; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.158.238.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001382; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.170.240.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001383; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.183.54.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001384; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.36.12.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001385; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"217.11.75.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001386; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"217.127.133.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001387; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.12.181.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001388; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.2.40.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001389; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.234.165.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001390; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.238.246.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001391; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.207.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001392; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.227.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001393; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.68.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001394; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.81.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001395; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.56.93.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001396; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.59.116.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001397; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.79.103.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001398; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.93.102.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001399; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.93.102.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001400; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.102.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001401; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.29.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001402; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.186.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001403; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.139.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001404; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.150.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001405; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.214.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001406; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.241.6.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001407; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.1.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001408; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.1.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001409; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.163.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001410; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.171.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001411; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.245.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001412; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.5.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001413; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.69.71.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001414; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.70.238.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001415; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.80.217.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001416; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.85.145.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001417; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"21robo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100001418; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.118.168.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001419; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.126.237.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001420; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.200.22.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001421; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.71.239.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001422; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.1.144.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001423; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.124.78.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001424; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.125.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001425; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.136.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001426; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.202.232.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001427; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.130.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001428; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.251.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001429; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.116.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001430; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.172.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001431; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.184.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001432; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.252.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001433; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.8.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001434; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.232.1.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001435; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.235.137.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001436; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.112.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001437; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.32.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001438; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.34.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001439; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.43.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001440; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.68.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001441; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.108.17.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001442; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.118.248.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001443; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.119.65.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001444; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.132.125.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001445; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.103.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001446; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.9.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001447; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.148.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001448; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.211.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001449; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.17.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001450; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.237.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001451; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.17.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001452; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.179.215.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001453; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.185.116.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001454; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.186.20.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001455; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.187.9.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001456; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.211.72.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001457; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.236.85.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001458; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.238.230.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001459; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.239.83.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001460; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.248.64.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001461; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.92.9.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100001462; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.95.190.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001463; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.99.171.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001464; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.131.201.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001465; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.166.117.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001466; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.167.118.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001467; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.225.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001468; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.234.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001469; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.5.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001470; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.73.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001471; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.115.118.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001472; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.125.186.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001473; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.126.120.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001474; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.228.143.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001475; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.24.213.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001476; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.149.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001477; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.21.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001478; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.95.89.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001479; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.103.74.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001480; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.11.141.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001481; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.119.158.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001482; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.137.147.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001483; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.137.233.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001484; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.152.235.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001485; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.158.25.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001486; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.176.206.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001487; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.184.1.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001488; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.192.191.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001489; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.225.114.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001490; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.227.190.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001491; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.35.245.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001492; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.39.181.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001493; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.39.34.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001494; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.42.229.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001495; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.45.4.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001496; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.51.91.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001497; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.53.163.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001498; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.53.163.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001499; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.89.140.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001500; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.1.245.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001501; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.1.245.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001502; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.105.106.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001503; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.105.152.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001504; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.116.84.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001505; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.14.211.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001506; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.14.81.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001507; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.141.218.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001508; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.147.29.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001509; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.147.40.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001510; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.184.251.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001511; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.193.196.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001512; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.193.217.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001513; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.149.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001514; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.159.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001515; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.192.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001516; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.210.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001517; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.22.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001518; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.23.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001519; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.232.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001520; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.3.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001521; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.34.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001522; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.110.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001523; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.140.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001524; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.32.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001525; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.201.183.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001526; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.202.182.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001527; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.102.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001528; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.116.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001529; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.154.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001530; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.165.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001531; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.185.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001532; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.213.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001533; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.255.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001534; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.28.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001535; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.4.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001536; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.68.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001537; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.7.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001538; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.87.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001539; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.94.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001540; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.204.253.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001541; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.205.178.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001542; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.136.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001543; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.154.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001544; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.80.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001545; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.151.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100001546; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.155.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001547; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.170.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001548; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.119.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001549; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.164.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001550; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.237.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001551; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.247.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001552; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.25.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001553; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.34.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001554; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.92.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001555; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.208.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001556; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.231.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001557; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.107.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001558; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.234.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001559; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.236.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001560; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.32.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001561; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.44.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001562; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.63.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001563; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.104.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001564; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.109.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001565; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.175.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001566; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.255.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001567; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.66.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001568; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.84.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001569; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.214.37.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001570; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.139.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001571; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.190.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001572; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.212.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001573; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.253.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001574; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.71.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001575; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.98.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001576; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.117.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001577; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.128.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001578; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.131.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001579; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.144.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001580; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.197.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001581; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.225.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001582; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.227.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001583; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.234.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001584; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.133.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001585; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.191.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001586; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.248.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001587; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.132.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001588; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.151.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001589; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.160.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001590; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.176.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001591; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.192.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001592; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.83.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001593; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.20.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001594; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.249.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001595; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.85.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001596; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.221.239.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001597; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.241.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001598; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.76.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001599; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.223.242.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001600; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.24.28.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001601; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.129.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001602; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.154.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001603; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.212.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001604; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.58.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001605; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.43.117.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001606; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.0.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001607; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.11.51.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001608; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.13.23.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001609; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.124.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001610; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.179.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001611; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.184.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001612; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.191.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001613; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.194.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001614; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.216.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001615; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.219.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001616; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.24.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001617; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.30.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001618; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.63.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001619; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.65.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001620; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.79.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001621; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.94.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001622; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.179.201.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001623; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.195.84.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001624; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001625; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001626; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.28.7.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001627; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.30.119.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001628; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32.208.157.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001629; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32792.prolocksmithwinterpark.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100001630; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"35.184.169.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001631; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.108.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001632; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.248.228.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001633; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.248.83.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001634; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.250.203.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001635; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.157.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001636; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.18.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001637; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.51.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001638; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.255.90.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001639; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.33.128.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001640; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.33.160.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001641; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.34.150.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001642; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.105.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001643; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.133.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001644; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.139.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001645; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.89.18.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001646; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360.lcy2zzx.pw"; content:"Host"; http_header; classtype:trojan-activity; sid:100001647; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360down7.miiyun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100001648; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.222.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001649; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.233.60.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001650; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.179.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001651; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.180.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001652; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.44.238.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001653; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.49.230.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001654; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.14.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001655; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.14.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001656; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.230.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001657; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"38.77.14.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001658; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.245.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001659; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.98.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001660; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.117.31.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001661; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.162.104.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001662; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.196.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001663; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.59.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001664; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.66.44.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001665; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001666; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.125.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001667; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.146.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001668; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.148.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001669; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.206.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001670; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.124.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001671; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.171.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001672; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.249.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001673; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.60.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001674; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.167.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001675; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.67.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001676; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.10.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001677; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.163.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001678; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.168.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001679; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.203.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001680; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.237.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001681; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.132.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001682; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.194.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001683; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.235.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001684; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.33.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001685; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.78.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001686; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.113.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001687; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.114.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001688; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.14.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001689; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.150.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001690; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.197.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001691; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.209.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001692; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.48.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001693; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.63.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001694; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.94.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001695; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.163.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001696; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.166.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001697; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.218.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001698; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.91.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001699; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.93.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001700; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.127.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001701; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.18.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001702; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.191.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001703; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.205.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001704; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001705; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.36.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001706; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.37.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001707; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.251.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001708; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.27.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001709; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.29.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001710; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.70.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001711; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.83.94.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001712; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.115.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001713; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.85.54.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001714; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.129.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001715; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.170.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001716; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.211.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001717; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.234.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001718; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.63.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001719; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.93.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001720; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.155.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001721; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.233.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001722; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.67.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001723; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.72.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001724; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.108.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001725; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.145.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001726; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.146.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001727; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.63.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001728; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.90.86.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001729; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"40.88.2.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001730; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.139.209.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001731; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.165.130.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001732; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.190.63.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001733; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.193.192.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100001734; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.219.185.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001735; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.226.60.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001736; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.72.203.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001737; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001738; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001739; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001740; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.202.101.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001741; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.39.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001742; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.43.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001743; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.65.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001744; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.82.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001745; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.232.81.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001746; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.180.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001747; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.239.26.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001748; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.56.15.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001749; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.61.99.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001750; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.82.217.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001751; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.84.37.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001752; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.241.106.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001753; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.241.108.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001754; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.252.8.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001755; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.115.172.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001756; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.1.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001757; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.203.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001758; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.135.134.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001759; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001760; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001761; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.141.84.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001762; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.141.84.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001763; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001764; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001765; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001766; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001767; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001768; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001769; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001770; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001771; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001772; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001773; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.164.140.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001774; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.165.215.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001775; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001776; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001777; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001778; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.110.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001779; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.22.209.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001780; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.229.53.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001781; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.23.22.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001782; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.248.194.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001783; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.27.253.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001784; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.51.104.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001785; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.6.24.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001786; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.81.235.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001787; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.85.90.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001788; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.9.148.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001789; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.92.108.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001790; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.117.42.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001791; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.172.75.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001792; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.182.173.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001793; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.20.63.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001794; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.214.27.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001795; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.24.130.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001796; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.241.120.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001797; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.243.179.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001798; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.249.33.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001799; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.25.242.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001800; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.118.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001801; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.86.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001802; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.97.76.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001803; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.103.219.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001804; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.145.152.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001805; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.151.23.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001806; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.157.97.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001807; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.16.131.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001808; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.21.202.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001809; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.46.231.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001810; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.119.187.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001811; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.162.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001812; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.87.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001813; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.143.43.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001814; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.156.35.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001815; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.158.201.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001816; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.20.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001817; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.21.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001818; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.174.182.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001819; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.170.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001820; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.178.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001821; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.179.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001822; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.68.221.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001823; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.188.62.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001824; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.2.70.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001825; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.53.146.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001826; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.79.75.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001827; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.95.226.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001828; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.115.174.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001829; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.115.174.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001830; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.121.91.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001831; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.252.47.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001832; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.114.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001833; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.180.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001834; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.114.246.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001835; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.162.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001836; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.174.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001837; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.125.191.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001838; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.126.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001839; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.141.122.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001840; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.166.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001841; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.200.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001842; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.143.189.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001843; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.218.67.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001844; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.22.212.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001845; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.226.129.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001846; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.230.89.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001847; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.238.42.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001848; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.240.147.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001849; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.241.78.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001850; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.243.126.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001851; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.243.208.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001852; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.142.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001853; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.79.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001854; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.84.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001855; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.48.154.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001856; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001857; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001858; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.76.151.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001859; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.97.206.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001860; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.0.211.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001861; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.102.168.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001862; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.202.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001863; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.214.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001864; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.237.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001865; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.246.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001866; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.23.114.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001867; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.58.117.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001868; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.18.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001869; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.96.37.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001870; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.169.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001871; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.10.91.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001872; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.13.61.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001873; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.164.130.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001874; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.175.124.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001875; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.20.217.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001876; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.208.135.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001877; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.122.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001878; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.186.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001879; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.216.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001880; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.233.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001881; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.6.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001882; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.100.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001883; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.111.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001884; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.202.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001885; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.206.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001886; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.218.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001887; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.220.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001888; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.254.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001889; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.162.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001890; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.83.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001891; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.195.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001892; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.177.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001893; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.86.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001894; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.223.84.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001895; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.15.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001896; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.4.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001897; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.51.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001898; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.60.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001899; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001900; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.26.104.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001901; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.10.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001902; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.8.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001903; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.99.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001904; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.164.96.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001905; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.91.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001906; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.247.224.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001907; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.253.94.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001908; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.41.230.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001909; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.47.220.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001910; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.103.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001911; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.199.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001912; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.30.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001913; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.9.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001914; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.99.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001915; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.117.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001916; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.89.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001917; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.103.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001918; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.64.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001919; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.69.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001920; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.180.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001921; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.181.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001922; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.57.96.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001923; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.170.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001924; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.73.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001925; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.61.218.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001926; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.65.172.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001927; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.0.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001928; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.104.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001929; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.110.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001930; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001931; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001932; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.255.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001933; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.45.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001934; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.98.144.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001935; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.1.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001936; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.141.73.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001937; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.131.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001938; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001939; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.155.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001940; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.227.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001941; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.31.126.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001942; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.149.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001943; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.222.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001944; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.43.207.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001945; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.90.165.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001946; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"63.245.122.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001947; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"64.233.154.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001948; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.125.128.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001949; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.21.58.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001950; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.26.155.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001951; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.35.61.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001952; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.229.214.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001953; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.57.55.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001954; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.74.7.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001955; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.97.181.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001956; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.245.151.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001957; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.3.169.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001958; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.8.138.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001959; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.83.49.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001960; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.84.138.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001961; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.148.103.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001962; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.151.244.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001963; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.174.182.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001964; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.175.107.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001965; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.188.144.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001966; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.204.88.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001967; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.106.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001968; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.119.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001969; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.78.33.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001970; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.115.37.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001971; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.120.237.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001972; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.123.245.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001973; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.124.231.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001974; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.127.214.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001975; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.146.232.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001976; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.165.173.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001977; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.196.158.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001978; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.222.157.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001979; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.229.0.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001980; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.63.73.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001981; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.115.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001982; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.227.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001983; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.76.240.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001984; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.115.31.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001985; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.118.240.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001986; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.167.10.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001987; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.236.190.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001988; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.25.5.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001989; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.93.129.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001990; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.127.148.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001991; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.146.190.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001992; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.204.63.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001993; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.29.48.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001994; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.34.191.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001995; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.40.234.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001996; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.106.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001997; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.2.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001998; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.235.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001999; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.47.133.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002000; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.71.60.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002001; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.85.106.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100002002; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.17.22.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002003; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.186.139.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002004; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.180.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002005; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.200.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100002006; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.202.249.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002007; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.214.69.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002008; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.229.230.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002009; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.31.40.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002010; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.204.216.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100002011; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.70.164.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002012; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.101.1.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002013; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.108.224.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002014; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.194.117.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100002015; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.195.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100002016; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.199.84.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002017; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.64.139.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002018; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.75.165.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002019; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.127.141.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002020; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.83.102.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002021; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.99.213.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002022; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.170.11.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002023; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.178.22.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100002024; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.217.92.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002025; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.250.199.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100002026; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.254.129.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002027; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.84.134.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002028; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.95.12.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100002029; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.111.182.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002030; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.237.25.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002031; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.50.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002032; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.52.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002033; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.89.203.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002034; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77st.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002035; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.145.224.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002036; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.186.155.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002037; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.141.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002038; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.240.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002039; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.41.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002040; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.168.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002041; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.188.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002042; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.104.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002043; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.176.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002044; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.27.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002045; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.23.172.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002046; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.8.225.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002047; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.11.195.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002048; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.13.49.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002049; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.130.253.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002050; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.147.123.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002051; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.175.42.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002052; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.21.84.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002053; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.7.170.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002054; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.79.58.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100002055; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.8.70.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002056; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.9.88.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100002057; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.107.89.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002058; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.19.101.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002059; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.211.181.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002060; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.217.12.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002061; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.99.128.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002062; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.136.146.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002063; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.165.44.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002064; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.191.40.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002065; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.213.141.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002066; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.215.199.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002067; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.187.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100002068; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.195.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100002069; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.237.128.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002070; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.244.219.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002071; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.246.225.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002072; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.92.36.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002073; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.103.108.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100002074; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.135.196.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002075; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.212.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002076; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.85.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002077; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.207.61.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002078; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.209.250.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002079; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.211.156.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002080; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.59.31.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002081; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.110.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002082; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.53.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002083; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.138.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100002084; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.139.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100002085; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.154.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100002086; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.187.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002087; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.100.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002088; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.106.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002089; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.108.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002090; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.131.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100002091; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.19.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002092; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.197.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002093; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.215.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002094; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.232.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002095; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.234.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002096; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.246.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002097; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.28.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002098; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.4.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002099; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.55.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002100; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.73.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002101; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002102; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.165.237.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002103; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.147.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100002104; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.218.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002105; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.242.253.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002106; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.252.9.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002107; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.210.219.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002108; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.212.219.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002109; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.50.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002110; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.95.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002111; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.238.24.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002112; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.247.83.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002113; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.254.39.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002114; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.33.111.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002115; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.39.248.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002116; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.40.127.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002117; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.42.20.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002118; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002119; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.11.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100002120; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.123.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002121; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.135.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002122; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.180.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002123; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.224.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002124; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.241.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002125; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.214.149.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002126; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.64.181.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002127; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.64.203.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002128; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.74.215.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002129; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.130.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002130; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.195.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002131; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"86.35.43.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002132; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.172.19.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002133; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.61.89.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002134; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.119.171.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002135; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.208.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002136; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.219.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100002137; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.225.222.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002138; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.247.96.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002139; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.136.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002140; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.51.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002141; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.249.244.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002142; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.204.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002143; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.226.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002144; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.240.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002145; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.254.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002146; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.122.183.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002147; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.136.197.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002148; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.22.152.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002149; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.29.213.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002150; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.85.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002151; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8poieq.bn.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002152; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"90.152.144.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002153; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.132.197.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002154; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.138.215.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002155; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.177.139.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002156; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.187.103.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002157; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.205.173.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002158; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.212.150.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002159; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.214.124.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002160; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.217.104.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100002161; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.233.112.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002162; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.239.168.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002163; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.92.16.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002164; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.98.4.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002165; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.114.191.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002166; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.241.78.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002167; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.27.246.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002168; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.54.237.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002169; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.83.62.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002170; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.85.18.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002171; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.159.169.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002172; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.21.224.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002173; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.39.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100002174; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.39.79.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002175; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.137.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002176; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.182.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100002177; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.206.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002178; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.57.43.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002179; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.73.99.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002180; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.136.69.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002181; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.143.53.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002182; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.154.17.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002183; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.200.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002184; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.224.83.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002185; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.53.120.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002186; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.85.0.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002187; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.132.129.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002188; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.154.20.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002189; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.158.19.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002190; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.113.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002191; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.113.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002192; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.201.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002193; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.60.146.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002194; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.66.196.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002195; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.9.120.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002196; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.239.73.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002197; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.47.147.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002198; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.68.140.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002199; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.96.199.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100002200; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.0.210.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002201; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.113.239.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002202; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.116.72.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002203; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.128.147.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002204; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.178.242.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100002205; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.30.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002206; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.150.245.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002207; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.33.195.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002208; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aatreefelling.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002209; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abad.tv"; content:"Host"; http_header; classtype:trojan-activity; sid:100002210; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abcd.bg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002211; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abissnet.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002212; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aboveandbelow.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002213; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absoftechworld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002214; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absupplies.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002215; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abyssos.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002216; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"academyshademani.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002217; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acbick.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002218; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"accesslinksgroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002219; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aceeprc.com.aceeprc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002220; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acellr.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002221; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acteon.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002222; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"activecost.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002223; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"addahealingmusic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002224; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002225; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.memengers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002226; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.erapor.smk-alasror.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002227; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.gentbcn.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002228; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.grandoceanvilla.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002229; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admission.kmctartskuttippuram.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002230; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adventureexplorer.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002231; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aeropilates.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002232; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afnan-amc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002233; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afoninblog.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002234; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afrimedspecialist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002235; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agemn.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002236; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenciadigitalwdys.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002237; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenda.gmelloinformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002238; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agentt.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002239; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agile8studio.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002240; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aiecons.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002241; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimnaukri.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002242; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aiqtest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002243; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aitorocio.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002244; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajpharmaholding.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002245; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajstudiollc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002246; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"akdvidyalaya.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002247; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"al-wahd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002248; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alasdemariposas.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002249; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alberts.diamondrelationscrm.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100002250; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alemelektronik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002251; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alena1971.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002252; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alexdubai.com.aldiabsteel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002253; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alka.institute"; content:"Host"; http_header; classtype:trojan-activity; sid:100002254; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"allforcreative.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002255; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alltheway.travel"; content:"Host"; http_header; classtype:trojan-activity; sid:100002256; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alpaylar.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002257; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"am-concepts.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100002258; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amamontajes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002259; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarresdeamorymaestroshechiceros.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002260; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarteargentina.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002261; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amos524.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002262; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ams.alvinasschools.org.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100002263; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anadelgbt.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002264; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anantam.net.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002265; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreelapeyre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002266; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andremaraisbeleggings.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002267; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreonemaia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002268; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002269; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002270; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreshconcejal.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002271; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelazgheibld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002272; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelsdetour.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002273; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angloteste.bigprime.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002274; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anhung1102.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002275; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anurontv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002276; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anysbergbiltong.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002277; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api-ms.cobainaja.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002278; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002279; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.quocbao.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002280; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apoolcondo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002281; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.adsensearticle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002282; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.explicitsurveys.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002283; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.prerana.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002284; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apps.saintsoporte.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002285; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aps-scribe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002286; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aps-sv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002287; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apsusa.aero"; content:"Host"; http_header; classtype:trojan-activity; sid:100002288; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"areyoulivingwell.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002289; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"artedibujoyarquitectura.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002290; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"arwenyapi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002291; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ask-regard.call-save.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002292; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atfile.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002293; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"athenacapsg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002294; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atlanticsteelprocessing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002295; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atlasconcreteworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002296; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"attach.66rpg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002297; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atteuqpotentialunlimited.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002298; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"augustair.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002299; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aulist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002300; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"automaticrefreshments.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002301; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"avadhanagames.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002302; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayahuascasp.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002303; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayamallah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002304; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aycconsultoriaempresarial.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002305; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azmeasurement.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002306; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"b2b.toptanakaryakit.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002307; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"backgrounds.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002308; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"badeggdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002309; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"balealgodon.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002310; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bangkok-orchids.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002311; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bangladeshunbound.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002312; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bary.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002313; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bash.givemexyz.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002314; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002315; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bavhome.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002316; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bbia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002317; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcmt.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002318; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcrg.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002319; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bdnextrend.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002320; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beanx88.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002321; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bearcatpumps.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002322; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beautincollagen.rs"; content:"Host"; http_header; classtype:trojan-activity; sid:100002323; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bekape.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002324; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beor360.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002325; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bespokeweddings.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100002326; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bestcarenepal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002327; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betone.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002328; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betycopaints.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002329; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beveragesmiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002330; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bhavaniengineering.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002331; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bigmikesupplies.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002332; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilbosaquet.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002333; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilhen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002334; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing.citywine.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002335; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing.rahitechnosoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002336; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"binoy.stalphonsamissionva.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002337; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"biometrico.gpotecnosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002338; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bioskey.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002339; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birdi.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002340; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birminghamlink.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002341; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bizztradingbot.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002342; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bl4n3.zadns.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002343; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.callensaxen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002344; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.cast.re"; content:"Host"; http_header; classtype:trojan-activity; sid:100002345; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.difusodesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002346; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.oyinblogs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002347; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.takbelit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002348; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bmlifestyle.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002349; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bnrnews.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002350; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"boatpecas.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002351; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bodenstein.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002352; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"booksearch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002353; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bophelocare.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002354; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bounces.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002355; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"boutiqueofferte.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002356; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bpo.correct.go.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100002357; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bradleyinstitute.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002358; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brandtrust.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002359; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"braunfinancial.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002360; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brendanquine.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002361; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brideofmessiah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002362; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightaffiliatesales.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002363; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightmega.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002364; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightstarshop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002365; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"browardinsurancemiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002366; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bt2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002367; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"btdapi.robotake.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002368; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buigiaphat.com.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002369; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bulkyfoodja.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002370; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bullseyemedia.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002371; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"busandvanrentalmalaysia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002372; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buscascolegios.diit.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002373; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"business.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002374; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"business2.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002375; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bydspa.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002376; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c.oooooooooo.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002377; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c0140529.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002378; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"caballo.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002379; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cacaoprojects.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002380; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"calgaryautorepairservice.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002381; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"callbury.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002382; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"camminachetipassa.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100002383; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"canadianwork.cc"; content:"Host"; http_header; classtype:trojan-activity; sid:100002384; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capitalgroup-kw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002385; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capoeiraventrelivre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002386; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cardilicores.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002387; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cashyinvestment.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002388; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"catchperch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002389; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"catchpoolshetlands.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002390; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cazyacustomfurniture.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002391; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cbn.hypervoizd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002392; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ccauthority.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002393; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cdaonline.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002394; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cec.asso.ac-amiens.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002395; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cecra.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002396; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cellas.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002397; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cendekiabinaaksara.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002398; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cfs5.tistory.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002399; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ch.rmu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100002400; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chance5.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002401; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"changematterscounselling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002402; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chardhamdodham.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002403; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"check.askwordpressguru.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002404; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chezalice.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002405; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"childselect.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002406; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002407; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002408; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chipmania.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100002409; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cible-energy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002410; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cifeer.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002411; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cirugiadenarizbucaramanga.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002412; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citihits.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002413; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citssolutions.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002414; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citycapproperty.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002415; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cityglobalgospel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002416; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"civi.istmejia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002417; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cleanbydesignllc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002418; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cloud.fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002419; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cm-arquitetos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002420; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"codsambal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002421; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colempaques.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002422; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colorpak.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002423; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"columbia.aula-web.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002424; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"community.reimclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002425; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"competancy.indigoconsult.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002426; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"conceptimagine.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002427; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"config.cqhbkjzx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002428; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"connectcapital.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002429; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"constructoralyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002430; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"consulateins.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002431; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"contributeindustry.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002432; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"controleautomacao.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002433; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"copelandscapes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002434; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"coulsongraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002435; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"count.mail.163.com.impactmedfoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002436; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"covid19.cyberschool.or.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002437; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cpanel.shivay.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002438; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr-sq.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002439; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"craftech.nxtnet.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002440; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"creationskateboards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002441; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crecerco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002442; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crittersbythebay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002443; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crm.notariavieitoyvelamazan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002444; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crmfarko.manivelasst.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002445; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crmroche.manivelasst.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002446; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crscorretordeimoveis.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002447; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cse-engineer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002448; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"csnserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002449; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cubescargoexpress.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002450; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"curasoles.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002451; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"currantmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002452; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cwa.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002453; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyclomove.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002454; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cynkon.kairoscs.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002455; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"czsl.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002456; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d.powerofwish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002457; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d9.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002458; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"da.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002459; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dagiionline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002460; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"damagedessentialtelecommunications.testmail4.repl.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002461; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"danaevara.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002462; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dartoonpictures.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002463; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.cdevelop.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002464; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.over-blog-kiwi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002465; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datapolish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002466; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dating.khokhas.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002467; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davethompson.me.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002468; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davidmcguinness.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002469; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dayspringdaisies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002470; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dd.qiyuea.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002471; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"de.gsearch.com.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002472; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"decifrar.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002473; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"deigratia2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002474; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dekovizyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002475; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo-cliente.mindcreative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002476; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo.glassforcars.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002477; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo.iiitindia.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002478; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo6.hiites.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002479; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dent-estet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002480; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dental.xiaoxiao.media"; content:"Host"; http_header; classtype:trojan-activity; sid:100002481; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dentalalliance.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100002482; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"desertlandtrd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002483; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"designerliving.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002484; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"desiringhands.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002485; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"despertaresi.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002486; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"destinymc.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002487; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"detorre.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002488; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.sebpo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002489; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.watch-store.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002490; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfcf.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002491; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfsfcsfcdsfsdvcfsvcscv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002492; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"diamantenegro.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002493; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dienmayminhhung.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002494; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"digilib.dianhusada.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002495; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"digisails.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002496; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"disinfection-cleaning.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002497; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"djking.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002498; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.1003b.56a.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002499; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002500; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.installcdn-aws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002501; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.packetstormsecurity.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002502; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.rina-roleplay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002503; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dnn.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002504; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dns.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002505; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dns.cyberium.cc"; content:"Host"; http_header; classtype:trojan-activity; sid:100002506; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dockerupdate.anondns.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002507; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"docman.orientalservices.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002508; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dodsonimaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002509; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"doitunlimited.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002510; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dokan.blueberrytec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002511; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom-chel74.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002512; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom.daf.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002513; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"doncedyhall.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002514; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"donghobinhminh.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002515; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dongphuctop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002516; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"donwnloasecury.ath.cx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002517; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002518; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosman.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002519; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dovberger.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002520; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.pcclear.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002521; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.postch-de.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100002522; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.postch-dl.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100002523; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.udashi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002524; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.webbora.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002525; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down1.arpun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002526; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.caihong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002527; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.doumaibiji.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002528; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.exrnybuf.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002529; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.kaobeitu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002530; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.pdf00.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002531; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.rising.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002532; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.skycn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002533; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.zjsyawqj.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002534; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dragonsknot.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002535; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drbaby.com.sa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002536; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dream.pics"; content:"Host"; http_header; classtype:trojan-activity; sid:100002537; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drgroup.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002538; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drools-moved.46999.n3.nabble.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002539; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drsha.innovativesolutions.mobi"; content:"Host"; http_header; classtype:trojan-activity; sid:100002540; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsdisplay.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002541; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsenterprize.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002542; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsspainting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002543; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"du-wizards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002544; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duanhaozhang.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002545; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duque.guantanameratravel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002546; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dutapp.wisolve.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002547; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duvalcharter.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002548; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dx.qqyewu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002549; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dzinestudio87.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002550; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-commerce.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002551; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002552; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eandgdesign.com.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100002553; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eastsheen-glaziers.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002554; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebruyatkin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002555; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"edu.saicraftsman.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002556; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eedo.ee"; content:"Host"; http_header; classtype:trojan-activity; sid:100002557; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"efficientegroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002558; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"elbauldenora.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002559; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"emaids.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002560; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"emaz.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002561; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"emlak.ygtsoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002562; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"en.baoend.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002563; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enc-tech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002564; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"endurotanzania.co.tz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002565; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ennovate.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002566; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enriquecendocomconsorcio.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002567; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"equimination.ee"; content:"Host"; http_header; classtype:trojan-activity; sid:100002568; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"erp.nanotechproautocare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002569; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"erp.zilymax.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002570; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"escola.probommar.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002571; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"esnconsultants.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002572; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"essentia.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002573; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eubanks7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002574; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"europeanzonexxi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002575; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"evidencemarketing.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100002576; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exilum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002577; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exitoalfaomega.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002578; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"extrovertoffers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002579; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"f1sol.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002580; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fahrzeugdrive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002581; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"familydentist.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100002582; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002583; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"felicienne.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002584; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"files.martellexpress.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100002585; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"filmotainment.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002586; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"final.makkahkmcc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002587; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fineartgallerym.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002588; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fisconline.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002589; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fix-america-now.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002590; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fixauto.illumetechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002591; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fixturegovernment.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002592; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fkd.derpcity.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002593; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flexypay.dsquaregroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002594; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flintspin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002595; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flyingbuddhadesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002596; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fmjplastering.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002597; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fms.buladde.or.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002598; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"follower.instantcashback.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002599; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foothills.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002600; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"footweardirect.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002601; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"forum.mdb.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002602; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fotoobjetivo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002603; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foxeps.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002604; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fraud.bpcbankingtech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002605; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freecnetdownload.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002606; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freisites.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002607; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ftp.n3twork30cm.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100002608; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fullelectronica.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002609; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"funletters.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002610; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fusionfiresolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002611; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"futuregraphics.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002612; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"g.pinmonkey.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002613; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gametwogame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002614; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garciadogshow.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002615; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002616; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow4.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002617; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gastoudergonny.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002618; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gbbulls.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002619; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gcpc.co.id.chronoscurtain.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002620; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"generaldeviales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002621; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfmodd1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002622; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfold1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002623; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghettohub.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002624; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghislain.dartois.pagesperso-orange.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002625; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giadungg7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002626; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giddos.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002627; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giteletropical.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002628; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"glowinmedia.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002629; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmsebpl.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002630; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmtransformationacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002631; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmvadmission.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002632; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnimelf.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002633; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnscrew.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002634; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gold.investforex.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002635; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcake.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002636; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002637; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002638; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"golden-memories-funerals.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002639; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldenasiacapital.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002640; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldmen.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002641; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gorecycle.fahadjutt.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002642; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gpotecnosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002643; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gracejukes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002644; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"grovershospital.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002645; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupoinmare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002646; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gruposelt.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002647; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gruppodomus.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002648; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gs.monerorx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002649; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"guide-to-cell-phones.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002650; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gulfac-house.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002651; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gvpcdpgc.edu.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002652; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"habbotips.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002653; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hagebakken.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100002654; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hamptonpartyoffive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002655; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hashmati.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002656; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hassanproduct.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002657; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hchfug.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002658; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hd11315.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002659; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hdkamera2003.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002660; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hds.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002661; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"heavymaq.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002662; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hellogorgeous.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002663; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"help.hizuko.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002664; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"herchinfitout.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002665; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hhaward.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002666; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandroadcoc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002667; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandslasvegas.atakdev.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002668; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hindi.factsriver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002669; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitpe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002670; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitstation.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002671; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hlmd.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002672; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hmpmall.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002673; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoagietesting10.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002674; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoayeuthuong-my.sharepoint.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002675; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"homefindersolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002676; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hongluosi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002677; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hookedupboatclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002678; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hortizwp.eastus.cloudapp.azure.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002679; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostingparacolombia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002680; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostzaa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002681; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"houstonshutters.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100002682; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hr2019.vrcom7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002683; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hrnautica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002684; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hseda.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002685; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"htownbars.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002686; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hubtech.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002687; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"huellacero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002688; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hunggiang.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002689; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"husamiyahschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002690; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iabmixx2020.rayadigital.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100002691; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iam313.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002692; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iammdshanto.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002693; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"icon.shatangmu.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002694; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idilsoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002695; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idj.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100002696; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idvindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002697; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ieclb.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002698; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ikexpert.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002699; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ilrafrica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002700; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"images.jermiau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002701; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"imbueautoworx.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002702; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"in-tune2016.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002703; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incrediblepixels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002704; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incredicole.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002705; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"indrasbikaner.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002706; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infair.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002707; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infovator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002708; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"initialnetworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002709; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inodesthetotaldesigners.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002710; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inrajahmundry.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002711; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"insignificantfinecore.testmail4.repl.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002712; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"instantindialoan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002713; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"insupportofchildren.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002714; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intellectsmart.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002715; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intersel-idf.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002716; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intuitiveideas.com.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100002717; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inversiones.arrayanfinanciero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002718; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"invest.xpcorporative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002719; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"investinae.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002720; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ioabc.wif.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002721; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ipmes.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100002722; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iremart.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002723; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iris101.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002724; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isaac.mikhailmotoringschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002725; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iscamenabe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002726; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isiphephelocon.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002727; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iso-dubai.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002728; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"israrulhaq.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100002729; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isrorg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002730; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isso.ps"; content:"Host"; http_header; classtype:trojan-activity; sid:100002731; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ist-security.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002732; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"it123.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002733; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"italiandirezione.casa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002734; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itc-demo.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002735; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itelsys.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100002736; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itmotasaciones.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002737; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jacktech.jackindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002738; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jaishritours.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002739; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamiekaylive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002740; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamshed.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002741; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jansen-heesch.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002742; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jathra.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002743; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jay.diamondrelationscrm.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100002744; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jebs.net.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002745; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jeffdahlke.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002746; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jennwolfemtb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002747; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jhayesconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002748; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jiaoyuzixun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002749; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jing-da.com.tw"; content:"Host"; http_header; classtype:trojan-activity; sid:100002750; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jmtc.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002751; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jnanbharati.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002752; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jobs.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002753; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"joelbonissilver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002754; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"join.cl8movement.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002755; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"josegene.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002756; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jpwoodfordco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002757; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jumpmanualjacobhiller.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002758; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jupiter.toxsl.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002759; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"justinscott.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002760; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kadigital.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002761; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kaizenjanitorial.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002762; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalawatihomes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002763; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalogirosfinance.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002764; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kaptaanchapal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002765; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"karer.by"; content:"Host"; http_header; classtype:trojan-activity; sid:100002766; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"katanvetov.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100002767; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kensingtondriving.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002768; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ketofitnessexpert.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002769; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kevinjewelry.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002770; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"keywatch.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002771; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kingssa.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002772; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kjcpromo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002773; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kleinendeli.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002774; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"korrectconceptservices.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002775; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"krisbadminton.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002776; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ktb.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002777; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kubatoglubaklava.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002778; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kumaralok.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002779; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kwanfromhongkong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002780; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kz.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002781; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lacasadelosalebrijes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002782; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ladylabonde.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002783; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lameguard.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002784; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laodongnhat.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002785; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laravel.pointersoftwares.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002786; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lasermobilesounds.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002787; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laura9630fr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002788; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lauratomismith.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002789; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lautarosanmiguel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002790; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lawforall.edu.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002791; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lawschoolideas.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002792; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lceventos.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002793; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ld.mediaget.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002794; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ldgcorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002795; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"learning.real-academy.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002796; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leasiacherise.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002797; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leczkregoslup.acelero.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002798; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"legend.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002799; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leluibuffet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002800; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lestesteux.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100002801; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"libantravel.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002802; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.arihantmbainstitute.ac.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002803; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.uib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002804; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lidoraggiodisole.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100002805; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lifebeam.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002806; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lindnerelektroanlagen.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002807; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"linkintec.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002808; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"liquidaz.casa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002809; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"livetrack.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002810; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsindian.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002811; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lm.stagingarea.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002812; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmaancha.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100002813; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002814; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.login2.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002815; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"location-voitures.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100002816; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.trezor.com.stockfootagesindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002817; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"logotypfabriken.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100002818; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotix.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002819; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotusanddragonfly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002820; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.definerisco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002821; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.difusodesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002822; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.quama.pe"; content:"Host"; http_header; classtype:trojan-activity; sid:100002823; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luckybrownie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002824; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luminouspneuma.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002825; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luxomodels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002826; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m-technics.kz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002827; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.estudiomoros.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002828; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.mobilelocalsales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002829; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.softsharks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002830; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"madicon.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002831; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"magianegramagiablancayamarres.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002832; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maharaniworld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002833; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.bs-eiendomme.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002834; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.golimoapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002835; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.jeffsono.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002836; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maksi.feb.unib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002837; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malaya.tv"; content:"Host"; http_header; classtype:trojan-activity; sid:100002838; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malwarecoding.github.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100002839; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managed.oss-cn-beijing.aliyuncs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002840; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managemysalon.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002841; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manantialesdelnorte.uy"; content:"Host"; http_header; classtype:trojan-activity; sid:100002842; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mangalyaa.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002843; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manhtien.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002844; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marcapinyo.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002845; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mario-sunjic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002846; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariobrown.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002847; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariotessarollo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002848; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketinfosales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002849; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marksidfgs.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002850; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"masjidhabeebiyarazviya.mysunni.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002851; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mastersofclientretention.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002852; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"masterthedaybook.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002853; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"materialescantu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002854; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"matruchhaya.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002855; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxiquim.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002856; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxoprint.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002857; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxtox.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002858; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbgrm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002859; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbjtimes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002860; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbsolutions.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100002861; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbx.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002862; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mdasa.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002863; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medevlb.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002864; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"media-server.skyinternet.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002865; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medianews.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100002866; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mediawaysnews.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002867; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medistaffconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002868; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meeweb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002869; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"megagynreformas.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002870; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"megamart.afnan-amc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002871; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mehainteriors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002872; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"melissaleiteestetica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002873; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mercabits.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002874; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"merkathink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002875; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mertlog.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002876; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"metaflip.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100002877; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"metalin-cr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002878; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mettaanand.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002879; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meuoculosnanet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002880; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mfevr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002881; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002882; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002883; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"micalle.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002884; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michaelphilip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002885; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michimal2.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002886; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microblading.mirliandias.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002887; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microcomm-group.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002888; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mikhailmotoringschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002889; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mills-skyla30ec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002890; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mingguanwms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002891; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"minuevavida.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002892; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mirror.mypage.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002893; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"misterson.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002894; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mkontakt.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100002895; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mktf.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002896; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmdx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002897; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmogollon.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002898; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mncarteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002899; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobile.illumetechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002900; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modelhouseturkey.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002901; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modernmanna.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002902; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"monetization.business"; content:"Host"; http_header; classtype:trojan-activity; sid:100002903; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"moninediy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002904; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mopai.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002905; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"moreirawag.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002906; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"motorcomunicacion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002907; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"msacontabil.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002908; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mtspsmjeli.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002909; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mumgee.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002910; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mundialdebienes.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002911; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mundotecnologiasolar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002912; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"musaffirtours.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002913; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"muzimbiti.xigubo.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002914; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mxpiqw.am.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002915; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mydatebook.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002916; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymlql.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002917; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myritz.vettickal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002918; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mysalons.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002919; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myscape.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002920; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mysura.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100002921; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"naeemacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002922; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"namnyak.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002923; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nap.mgsservers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002924; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"narcissisto.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002925; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"narimohol.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002926; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"navayurveda.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002927; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nec-i.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002928; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nedkellymyanmar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002929; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nelitrianggraeni.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002930; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nellaimasthanbiryani.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002931; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nerve.untergrund.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002932; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nettube.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002933; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"networkwheels.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002934; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neuroenergy.fahadjutt.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002935; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neuromedic.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002936; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newfuture.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002937; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newinfinitysynergy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002938; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newtreedesign.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002939; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newvisionopticallab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002940; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newxing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002941; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nextdigitalday.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002942; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ngdaycare.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002943; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nguyenkekhuyen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002944; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nhorangtreem.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002945; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nicolas.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002946; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nidhi.iexist.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002947; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nikanpolimer.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100002948; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilehouse.co.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002949; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilinkeji.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002950; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nimboohomes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002951; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"njtiledesigncenter.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002952; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nobius.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002953; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocalnoodle.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002954; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nomadicbees.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002955; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"notamuzikaletleri.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002956; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ns1.the-widyantos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002957; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsb.org.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002958; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nurmarkaz.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002959; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nxtnet.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002960; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nyasabigbullets.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002961; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nyeh2o.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002962; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oakleyandfriends.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002963; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"obseques-conseils.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002964; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oecteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002965; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohe.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100002966; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohsewgorgeous.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002967; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oknoplastik.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002968; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oleholeh.memangbeda.website"; content:"Host"; http_header; classtype:trojan-activity; sid:100002969; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002970; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaromatic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002971; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omega.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100002972; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oms.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002973; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omscoc.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002974; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedigitalcard.granvizionnecorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002975; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedrive.listifyapp.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002976; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"online.creedglobal.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002977; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinestatis.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002978; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"open.rawntech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002979; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"open.warehousesaas.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002980; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"opentoronto.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002981; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"opolis.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100002982; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"opticaoptigral.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002983; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"optimus.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002984; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"order.bizpeed.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002985; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orientgatewayltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002986; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orion445.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002987; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oserve.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002988; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ot.weenets.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002989; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"otolithenrichment.fahadjutt.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002990; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"outletdosaquecedores.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002991; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ozemag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002992; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p1.lingpao8.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002993; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p3.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002994; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p6.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002995; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pablobrothel.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002996; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacificgroup.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100002997; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacwebdesigns.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002998; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pagos.krayem.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002999; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"palbas.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003000; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"palochusvet.szm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003001; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pamperpartypros.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003002; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parallel.rockvideos.at"; content:"Host"; http_header; classtype:trojan-activity; sid:100003003; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parejasfelices.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003004; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parkhussion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003005; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"partharaj.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100003006; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"partsapp.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003007; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pastorpaulocosta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003008; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.51lg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003009; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003010; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch3.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003011; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paths.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003012; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patriotsupremehemp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003013; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paulmercier.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003014; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payerrealty.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003015; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payments.atifsiddiqui.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100003016; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pcsoori.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003017; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pd.oceaniarp.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003018; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pemdodo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003019; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perfumeriamontes.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100003020; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"periodiche.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003021; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpus.onlineman7-jombang.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003022; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpustekim.untirta.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003023; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pestoclean.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003024; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"petercollie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003025; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"petroindia.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003026; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ph4s.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003027; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phasdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003028; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phenhuong.sanpham.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100003029; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phittc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003030; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"photo360.kubooking.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003031; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pink99.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003032; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pinkpaprika.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003033; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"plasfan.ind.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003034; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"platinumherbal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003035; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"playground2.grupoaliadasca.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003036; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pmglance.startwriteup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003037; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pointactionsg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003038; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pokojewewladyslawowie.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003039; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pole.com.vc"; content:"Host"; http_header; classtype:trojan-activity; sid:100003040; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ponchokhana.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003041; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pool.phxdir.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003042; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pooltablemoversdenver.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003043; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"portal.premiumpunch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003044; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"posmicrosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003045; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"poulman.panagiotopoulos-tours.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003046; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ppdb.smk-ciptaskill.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003047; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestasicash.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003048; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestigehomeautomation.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003049; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"preview2.behalen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003050; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prishaartcreations.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003051; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prismaxis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003052; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"production.sparshims.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003053; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"programaoperadoronline.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003054; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"project.exquitec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003055; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promotapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003056; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promotoradescomplica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003057; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promoversdubai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003058; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003059; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003060; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosoc.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003061; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosupport.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003062; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosyarmakassar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003063; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"provence.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003064; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prueba.danielluza.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003065; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pujashoppe.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003066; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punchdialogues.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003067; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punjabdevelopersassociation.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003068; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pvcprinting.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003069; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qadir.tickfa.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003070; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qatarglobalconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003071; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qmsled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003072; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"quartier-midi.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100003073; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"querocar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003074; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rachmat-assuhaimi.my.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003075; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"radioafifense.deploys.live"; content:"Host"; http_header; classtype:trojan-activity; sid:100003076; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rainbowisp.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003077; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rajeshtailang.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003078; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakeshkhatri.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003079; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"raodigitalmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003080; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"raquelhelena.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003081; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rarlabarchiver.ac"; content:"Host"; http_header; classtype:trojan-activity; sid:100003082; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rasadbar.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003083; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rashika.ascarvalho.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003084; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ratemyfenancialadvisor.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003085; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ravenproductionsltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003086; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rc.ixiaoyang.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003087; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rcmesilva.charbelsales.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003088; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reacredit.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003089; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"readymmade.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003090; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"recyclethesurplus.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003091; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"redbats.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003092; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"redchillicrackers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003093; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reifenquick.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003094; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"relaxindulge.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003095; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"renehavis.com.ua"; content:"Host"; http_header; classtype:trojan-activity; sid:100003096; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"repatriacioncolombia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003097; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"res.uf1.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003098; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reseller.digimitra.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003099; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reseller.itechbrasil.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003100; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"resuco.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003101; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rezkabum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003102; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rhema.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100003103; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"richmondminerals.co.zm"; content:"Host"; http_header; classtype:trojan-activity; sid:100003104; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinaefoundation.org.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003105; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinkaisystem-ht.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003106; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"riverfox.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003107; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkcable.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003108; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkverify.securestudies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003109; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertmcardle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003110; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertsinclair.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003111; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ronnietucker.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003112; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roomsvc.servegate.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003113; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roshnijewellery.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003114; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rsgym.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003115; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubazar.pro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003116; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubycityvietnam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003117; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruisgood.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003118; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruwadalkuwait.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003119; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rydchile.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003120; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.thechinesemuslim.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003121; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sac2.11xii.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003122; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sacredscentsonline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003123; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sadmahfuneralservices.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003124; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safcol-colors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003125; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safehubsecurity.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003126; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safety.nanotechproautocare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003127; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sahathaikasetpan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003128; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sainzim.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003129; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"saisoftwareinc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003130; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"salecorner.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003131; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"salonsaifa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003132; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"samriddhijyotish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003133; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sandovalgraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003134; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"santyago.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003135; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sasystemsuk.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003136; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scaladevelopments.scaladevco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003137; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scarfaceindustries.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003138; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scglobal.co.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003139; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schalke04rss.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003140; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scheff.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003141; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schoolbustracker.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100003142; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sculetus.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003143; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-doc-reader.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003144; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"segalsmetals.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003145; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sellmyphonela.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003146; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"selltechtoday.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003147; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"senbiaojita.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003148; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sentierodelviandante.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100003149; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"serendibsourcing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003150; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sericaasia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003151; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003152; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003153; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviciovirtual.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003154; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sexologistpakistan.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003155; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"seyranikenger.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003156; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgb.ac.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100003157; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgessy.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003158; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shaheentbfoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003159; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shahikhana.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003160; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shahu66.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003161; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharkrigs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003162; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharpelevators.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003163; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shembefoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003164; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shivakunwar.com.np"; content:"Host"; http_header; classtype:trojan-activity; sid:100003165; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shoblasaathitrust.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003166; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shooka-co.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003167; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shop.goldspot.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100003168; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shopsofe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003169; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shrinikelectrical.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003170; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sibernetix.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003171; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sige.brisainformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003172; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"signatureads.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003173; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siili.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003174; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simoneporzi.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100003175; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simorsint.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003176; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simplithy.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003177; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindicato1ucm.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003178; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindpol.tiejuris.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003179; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sinergidwireka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003180; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sipahielektrik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003181; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sistelligent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003182; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skare.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003183; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyflyfares.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003184; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyscan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003185; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarthouseforum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003186; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smartzedu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003187; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smokesolutionindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003188; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smritiphotography.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003189; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sobariko.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003190; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sobethuacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003191; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.110route.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003192; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.officelabo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003193; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"softanis.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003194; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sogecoenergy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003195; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sohs.conceptechs.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003196; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"solar.amazingtribe.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003197; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somcorbera.cat"; content:"Host"; http_header; classtype:trojan-activity; sid:100003198; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somir.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003199; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soralapps.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003200; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sota-france.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003201; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"space.proactint.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003202; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spaceframe.mobi.space-frame.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003203; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"special-key.cf"; content:"Host"; http_header; classtype:trojan-activity; sid:100003204; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spent.com.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003205; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spetsesyachtcharter.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003206; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spiritualroot.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003207; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spititourism.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003208; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spittinfire.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003209; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sports-net.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003210; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"src1.minibai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003211; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sreenivasapaintingworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003212; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sriglobalit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003213; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"srilankamovies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003214; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"srvmanos.no-ip.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003215; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ss.monita.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003216; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"st.devcodin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003217; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"staging.apparelpunch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003218; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"starcountry.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003219; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"static.3001.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003220; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stiau.iuc.ac"; content:"Host"; http_header; classtype:trojan-activity; sid:100003221; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sticker.jewsjuice.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003222; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stiepancasetia.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003223; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stlukesohag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003224; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"store.ericalgarin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003225; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stott-thompson.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003226; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stratexec.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003227; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"suboldesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003228; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sumerians.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003229; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunaryem.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003230; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunbrero.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003231; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunmarkholidays.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003232; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"supermercadostia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003233; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-4-free.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003234; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support.clz.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003235; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"supportit.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100003236; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sw.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003237; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweaty.dk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003238; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweet-diet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003239; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swiftlogisticseg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003240; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swwbia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003241; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"syracusecoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003242; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sytraders.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003243; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"t.honker.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003244; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"t.netcatkit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003245; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tacticohosting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003246; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tadoo.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003247; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tafsantoursandtravels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003248; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tajushariya.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003249; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tallyinvoicecustomization.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003250; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taltus.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003251; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tapalkoedacoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003252; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tarravalleyfoods.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003253; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taurus.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003254; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tavo.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003255; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taxicabsrilanka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003256; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tc.snpsresidential.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003257; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tcy.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003258; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tdsp.yngw518.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003259; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tech332.synology.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100003260; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"techgms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003261; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teduae.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003262; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teleargentina.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003263; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"telescopelms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003264; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tencoconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003265; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teneth.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003266; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tentandoserfitness.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003267; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tessrobins.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003268; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.adventser.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003269; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.letraele.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100003270; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.lubrico.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003271; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.typoten.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003272; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.wanepghana.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003273; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.asistencia247.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003274; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.milenial.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003275; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100003276; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.basis-web.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003277; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.marrenconstruction.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100003278; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.clickitsolutionsmw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003279; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.thinkingcorp.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003280; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testnew.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003281; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testuat.itmoregistry.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003282; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teteaffiche.stephanebillon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003283; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tewoerd.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003284; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"textile.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003285; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tharringtonsponsorship.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003286; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theatretalkies.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003287; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecleaningladiespdx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003288; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecreativecafe.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003289; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thedesertship.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003290; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thediasporianexperience.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003291; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefirmlawgroup.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003292; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefuturelife.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003293; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thehighlightinterior.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003294; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thekassia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003295; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"themansionkasauli.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003296; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theprofinn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003297; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thesummitpc.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003298; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theurbantutors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003299; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thirdstringcalifornia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003300; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thosewebbs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003301; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thriveink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003302; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tianangdep.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003303; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickfoods.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003304; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tienda.ventadigital.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003305; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"timamollo.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003306; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"timegonebuy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003307; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tksb.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003308; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tlcc.com.gt"; content:"Host"; http_header; classtype:trojan-activity; sid:100003309; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"todoapp.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003310; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"todocontodo.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003311; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonydong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003312; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonystram.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003313; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonyzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003314; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tooba.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100003315; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tools.reimclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003316; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topcell9.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003317; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toplevel.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003318; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topmask.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003319; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"torresquinterocorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003320; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toyotacollege.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003321; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpef.lsoftdemo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003322; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpke.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003323; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"translaterjemah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003324; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"travelwithmanta.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003325; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trendyshoes.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003326; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trezors.io.mahlongwa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003327; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trimestre.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003328; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"triplonet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003329; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"troki.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003330; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tropics.codeleek.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003331; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trudelfavreau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003332; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsd.jxwan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003333; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tulli.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003334; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tupperware.michaelroberge.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003335; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"turanggaresources.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003336; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"txtdust.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003337; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uat.indianfilmzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003338; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ublretailerdemo.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003339; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uc-56.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003340; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uisusa.uisusa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003341; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ultimate-24.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003342; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"umwelt-kirchhof.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003343; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unicorpbrunei.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003344; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uniengrisb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003345; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unisoftcc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003346; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unyazitelecom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003347; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"upcbpta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003348; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"urbantrapfest.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003349; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"usamyforever.azureedge.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003350; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"used-jeans.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003351; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"useformoney.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003352; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"usmadetshirts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003353; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uss.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003354; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uzzepay.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003355; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vanzare.cabanabrazi2.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003356; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vbcargo.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003357; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vcah.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003358; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vectarts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003359; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vegadelcasero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003360; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"velma-harber30ku.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003361; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vendas.lidiacarmeli.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003362; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"versualstudio.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003363; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"veterinariadrpopui.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003364; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vfocus.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003365; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vienen.gblix.srv.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003366; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vilaart.rs"; content:"Host"; http_header; classtype:trojan-activity; sid:100003367; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villamarand.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003368; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villatera.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003369; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"violinstop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003370; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"virtuleverage.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003371; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visions.alnisamart.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003372; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visualhome.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003373; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vitoriamodaintima.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003374; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vivationdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003375; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"viveirodoiscorregos.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003376; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vksales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003377; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vocalterra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003378; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vokasi.ub.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003379; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vologroup.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003380; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"voteyouramerica.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003381; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vpinversiones.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003382; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vpts.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003383; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vstsample.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003384; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vtube.fadlymotivator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003385; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vvsskmodinationalschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003386; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003387; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepliberia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003388; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepniger.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003389; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weareactum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003390; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.eng.ubu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003391; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.geetle.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100003392; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.geomegasoft.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003393; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.newinnovationtechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003394; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.smarts-works.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003395; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003396; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webgis.perumdasolo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003397; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmailwindstreamnetmessagesecureapp1rqr.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100003398; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webpresario.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003399; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"website-work.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003400; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weinsteincounseling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003401; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wfinance.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003402; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whcms.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003403; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whiteresponse.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003404; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wi522012.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003405; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wikalen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003406; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildnights.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003407; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildtrust.mediadevstaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003408; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"willow-nettica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003409; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wimbamusica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003410; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"windcomtechnologies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003411; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wishesconcierge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003412; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woezon.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100003413; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wolfgang-brodte.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003414; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wonderhawaii.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003415; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woodsytech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003416; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wordpress.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003417; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"workingsolutionsrome.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003418; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wozata.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003419; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wp.readhere.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003420; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wpdemo.101clients.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003421; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"writtendeer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003422; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ws5588.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003423; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wsdyrmtcntlfarmtwsvb.dns.army"; content:"Host"; http_header; classtype:trojan-activity; sid:100003424; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wyklej.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003425; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"x-iting.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003426; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"x2vn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003427; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xia.beihaixue.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003428; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xixaoclothing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003429; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xk.996is.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003430; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--80akinnkiib6h.xn--90ais"; content:"Host"; http_header; classtype:trojan-activity; sid:100003431; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--polimerbizmimarlk-rvc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003432; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ybom.urbanolab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003433; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yeichner.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003434; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ylfpremium.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003435; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yoast.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003436; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yourclub1.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003437; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yourtopdog.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003438; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"youtubetrainingacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003439; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yskadvisors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003440; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yummyyogaudaipur.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003441; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yzkzixun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003442; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zmedcoach.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003443; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003444; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zz.690tx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003445; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100003446; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/86.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100003447; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c64.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100003448; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; http_uri; nocase; content:"amumufree.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003449; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/files/proxyi.exe"; http_uri; nocase; content:"analogx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003450; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003451; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dvdfv/anjj/downloads/jami.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003452; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/johnhast/efve/downloads/versiumr.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003453; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/johnhast/efve/downloads/versiumrr.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003454; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/4.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003455; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/6.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003456; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/labesoftware/update/downloads/boost-fps.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003457; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/labesoftware/update/downloads/install_plugin_x64_x86.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003458; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/labesoftware/update/downloads/vpn_free.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003459; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/clr.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003460; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatev.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003461; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/work.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003462; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/component.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003463; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003464; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/regsvc.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003465; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/skygaming/updates/downloads/update.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003466; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/001.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003467; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1488.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003468; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1_cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003469; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003470; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1fc2d.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003471; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/26a5.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003472; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003473; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/abjects.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003474; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/attached.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003475; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/b7f2c.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003476; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/battletext.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003477; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003478; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003479; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003480; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_makros.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003481; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_silent.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003482; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_sup.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003483; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003484; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003485; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003486; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildss.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003487; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientnik.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003488; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientrevers.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003489; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dcrat.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003490; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003491; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003492; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hans.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003493; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hulu.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003494; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfive.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003495; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfour.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003496; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelone.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003497; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelthree.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003498; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/inteltwo.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003499; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003500; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/kleiman.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003501; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003502; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/notepadplus.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003503; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003504; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003505; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003506; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003507; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/putty.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003508; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/rockethcd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003509; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/scvhost900.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003510; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/sessionwin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003511; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/siliculose.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003512; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/statemobi.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003513; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003514; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003515; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stgedo.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003516; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/svcperf.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003517; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003518; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurjok.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003519; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurusbabac.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003520; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/telekiller.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003521; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateandr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003522; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/vhajeja.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003523; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/word.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003524; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/www.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003525; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/xlsd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003526; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003527; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003528; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hmatrix/data/hack1226.exe"; http_uri; nocase; content:"cd.textfiles.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003529; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003530; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/816070119281131570/816070273254162442/all.txt"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003531; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/825372018244583454/826848185246023750/loaddd.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003532; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/825372018244583454/826848348342059008/zeppelin.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003533; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/825372018244583454/826848405258633277/build.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003534; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/826198252025675816/826537386485612574/china.png"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003535; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003536; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003537; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/razor/rzr-winner_intro.zip"; http_uri; nocase; content:"chiptune.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003538; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003539; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003540; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/meteoradminz/hidden-tear/zip/master"; http_uri; nocase; content:"codeload.github.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003541; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; http_uri; nocase; content:"colfincas.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003542; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/qz0h69.pdf"; http_uri; nocase; content:"deepfreedom.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003543; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ktcghnmcwws43wzscphukbfnwtuaxidx&revid=0b8z0b7_i5sirk2xrtehmstg0vxvit3b4n3lmbdrdrjrodndrpq"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003544; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; http_uri; nocase; content:"drive.google.com.it-barcelona.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003545; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003546; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=12khl-unz2np4q54b2jgpwlsh6cuz0pss"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003547; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=13sfskplrox3d7uantwjj_trs6ciwvqa1"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003548; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003549; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=152yoztzpbx_bbpxepfackfklg8c1eao6"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003550; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=15hcgek7odccdafzf-9gvibnlgkirj4uo"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003551; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003552; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=194lqzukzvt-jtdxmihcvhd0yk1sxoybk"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003553; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003554; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003555; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1br5iufkkmmfeipqo3ecviqykbcdgcnio"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003556; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003557; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1cos43rmscrescxk3u40qjuqbwr-pydsn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003558; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003559; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1dnm3wtjf6ud5fv6zop9cvbr4rs2of1-n"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003560; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1dqin1sdd6rbah3sggzsxzeqgrkmhjnqm"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003561; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003562; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1fensc6gc0fww0gbevsrnwwnlajypzdvv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003563; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1htinwtfrw1wc3_ma8odztnq0qpnic2q6"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003564; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003565; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003566; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003567; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1jkov2g5s1xkcq4bfb3uvmd6inhadatrg"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003568; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1jnarxelz8gtbkg5pa_s0rc8kv3ejkepn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003569; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1kjcylye1dbmhystyyotz-3pagktkhlhq"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003570; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1lsv4sko083sywwjndgqnsh_6sgqodqtu"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003571; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1mwgdd3lxuuk-bnsrm1rpclom0cmx7wob"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003572; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003573; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003574; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1nmf6kty3xsoygjxjhb-bsafvlfy-0lt2"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003575; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003576; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1p5fvqkxzwoiu_uauzbmrxpklsetculad"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003577; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003578; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1q1dwckludrpqijtrpw14_60d5nu7n97t"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003579; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1r9f9irwhutxozsbp2h9erd_a7fa2pwko"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003580; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1s221a6wpx6i7nfrztnhh9priojtybuxq"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003581; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1sjvkrinuscxqmbkdeusxaezazbiagnv3"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003582; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1so1trfuzt5-giahetghfhmd-_ot3rq35"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003583; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003584; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003585; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1uowridpynurgqlgqjbtgramigo2a9v76"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003586; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003587; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003588; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vjq92eqivh01yxmal20whl2es3ld6nxb"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003589; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003590; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003591; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003592; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003593; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003594; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yqpuxjbnjokc5fjgt-8xzuybr97rtvg2"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003595; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ywkgalidldb32pio6ywmbyvdk7oar3yy"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003596; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003597; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003598; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/1zilg/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003599; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/qcgfmfvh/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003600; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/emclick.zip"; http_uri; nocase; content:"e-mudhra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003601; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003602; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003603; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/x/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003604; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003605; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003606; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003607; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003608; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; http_uri; nocase; content:"file.elecfans.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003609; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003610; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003611; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; http_uri; nocase; content:"gist.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003612; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/7991.js"; http_uri; nocase; content:"hostingcloud.racing"; content:"Host"; http_header; classtype:trojan-activity; sid:100003613; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; http_uri; nocase; content:"hqdecig.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003614; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/suy/"; http_uri; nocase; content:"hsecaravans.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003615; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/19/items/startup_20210219/startup.txt"; http_uri; nocase; content:"ia801802.us.archive.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003616; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/online-timer-kvhxz/ilxl/"; http_uri; nocase; content:"ie-best.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003617; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100003618; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100003619; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ebook/cs17.exe"; http_uri; nocase; content:"jcedu.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003620; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003621; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003622; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003623; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; http_uri; nocase; content:"karmakoincodes.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003624; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dg/etrac/nf4emwz/"; http_uri; nocase; content:"kotakwarna.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003625; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe"; http_uri; nocase; content:"ksh.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003626; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/down/affiliate/kuaizip_setup_10029.exe"; http_uri; nocase; content:"kuaizip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003627; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/linuxforensicscode.zip"; http_uri; nocase; content:"linuxforensicsbook.com.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003628; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ds/1802.gif"; http_uri; nocase; content:"marcostrombetta.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003629; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/k/big5/1giof6/"; http_uri; nocase; content:"minpic.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003630; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-contentbak/t9m/"; http_uri; nocase; content:"morrobaydrugandgift.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003631; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ds/0204.gif"; http_uri; nocase; content:"moumitas.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003632; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; http_uri; nocase; content:"my.cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003633; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/aacenc.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003634; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/doxillionsetup.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003635; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/4/1/6/6/4166984/keygen.exe"; http_uri; nocase; content:"newyarlfm.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003636; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; http_uri; nocase; content:"nhipcauytevietnhat.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003637; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; http_uri; nocase; content:"note.youdao.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003638; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; http_uri; nocase; content:"oldschoolvalue.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003639; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003640; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003641; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21108&authkey=acq44gahejhwrag"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003642; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003643; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003644; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003645; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003646; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003647; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003648; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003649; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003650; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003651; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003652; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003653; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003654; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003655; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003656; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003657; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003658; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003659; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003660; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003661; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003662; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003663; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003664; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003665; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003666; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003667; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003668; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003669; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d!184&authkey=ackbiiarirejcam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003670; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d%21184&authkey=ackbiiarirejcam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003671; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003672; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003673; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003674; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003675; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0!1667&authkey=an8otd7jzc7xgho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003676; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0%211667&authkey=an8otd7jzc7xgho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003677; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0da4ace18aa7d1e2&resid=da4ace18aa7d1e2%21131&authkey=adjn1y5pp4a10_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003678; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003679; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003680; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003681; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003682; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003683; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003684; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003685; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003686; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003687; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f!286&authkey=almwisomhv3c0zc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003688; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003689; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003690; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003691; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003692; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003693; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003694; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003695; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003696; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003697; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003698; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003699; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003700; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003701; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003702; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003703; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003704; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003705; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003706; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003707; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!140&authkey=apn44x6bxlzq3ac"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003708; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!151&authkey=aeuk7knodrpenek"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003709; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!153&authkey=ao6e8g0bzbp_idw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003710; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!154&authkey=ah4chedbotzpmtq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003711; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!156&authkey=ajnqscnmrdonpkg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003712; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003713; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003714; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003715; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003716; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21140&authkey=apn44x6bxlzq3ac"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003717; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21151&authkey=aeuk7knodrpenek"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003718; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21153&authkey=ao6e8g0bzbp_idw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003719; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21154&authkey=ah4chedbotzpmtq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003720; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21156&authkey=ajnqscnmrdonpkg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003721; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003722; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003723; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003724; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003725; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003726; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003727; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003728; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2968c371f5450503&resid=2968c371f5450503!122&authkey=aaqhhxbnwfwrz28"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003729; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003730; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003731; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003732; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003733; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003734; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003735; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003736; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003737; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003738; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003739; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003740; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003741; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003742; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003743; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003744; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003745; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003746; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003747; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003748; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003749; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1!223&authkey=aajr842bzum0yg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003750; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003751; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003752; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003753; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003754; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003755; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003756; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003757; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003758; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003759; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003760; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003761; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003762; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003763; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003764; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003765; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003766; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003767; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3ee68228c34c236d&resid=3ee68228c34c236d%21129&authkey=apll6hu3-xetzxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003768; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003769; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003770; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003771; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba!2203&authkey=ajvalmr5l8epwvm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003772; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba%212203&authkey=ajvalmr5l8epwvm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003773; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003774; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003775; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003776; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003777; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003778; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21141&authkey=aazwaw2xjms24o0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003779; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003780; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003781; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003782; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003783; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003784; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003785; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003786; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003787; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003788; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003789; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003790; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003791; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003792; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003793; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003794; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003795; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003796; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003797; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003798; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003799; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003800; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003801; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003802; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003803; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003804; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003805; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003806; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003807; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003808; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003809; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003810; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003811; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003812; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003813; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003814; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003815; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003816; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003817; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003818; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003819; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003820; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003821; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003822; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003823; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003824; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003825; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003826; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003827; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003828; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003829; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003830; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003831; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003832; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003833; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003834; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003835; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003836; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003837; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003838; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003839; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003840; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003841; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003842; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003843; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003844; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003845; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003846; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003847; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003848; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003849; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003850; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003851; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003852; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003853; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003854; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003855; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003856; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003857; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003858; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003859; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003860; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003861; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003862; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003863; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003864; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003865; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003866; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003867; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003868; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003869; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003870; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003871; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003872; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003873; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003874; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003875; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003876; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003877; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003878; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003879; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003880; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003881; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003882; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003883; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003884; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003885; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003886; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21198&authkey=akq4jrbjm6spd9m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003887; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!109&authkey=ap-okubj9bvtlc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003888; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21106&authkey=an9dhtmtufpis-m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003889; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21109&authkey=ap-okubj9bvtlc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003890; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003891; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003892; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003893; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003894; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003895; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003896; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003897; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2!517&authkey=akfewcyiwlwomyk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003898; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003899; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21517&authkey=akfewcyiwlwomyk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003900; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003901; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003902; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003903; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003904; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003905; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003906; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003907; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003908; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003909; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003910; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003911; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003912; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003913; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003914; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003915; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003916; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003917; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!301&authkey=abquzhtdjg5pryk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003918; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!302&authkey=al2_xstzqulnnqw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003919; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!305&authkey=an-uuhplpk2zp5u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003920; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21301&authkey=abquzhtdjg5pryk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003921; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21302&authkey=al2_xstzqulnnqw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003922; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21305&authkey=an-uuhplpk2zp5u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003923; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003924; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003925; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003926; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003927; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003928; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003929; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003930; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003931; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003932; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!106&authkey=ahu5s4ttjvxbnxo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003933; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!107&authkey=abj3eccentbeaqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003934; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!108&authkey=amvcygo4prlgt4i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003935; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!110&authkey=ahzuehvk5nvzo90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003936; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21106&authkey=ahu5s4ttjvxbnxo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003937; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21107&authkey=abj3eccentbeaqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003938; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21108&authkey=amvcygo4prlgt4i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003939; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21110&authkey=ahzuehvk5nvzo90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003940; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003941; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003942; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003943; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003944; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003945; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003946; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003947; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003948; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125570&authkey=aejqgjglwurnb0a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003949; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003950; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003951; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003952; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003953; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003954; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003955; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003956; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003957; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003958; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003959; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003960; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003961; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21444&authkey=abzxvycu0ggtmg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003962; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003963; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003964; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003965; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003966; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003967; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003968; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003969; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003970; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003971; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003972; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003973; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=89360b4c7415c088&resid=89360b4c7415c088%21106&authkey=akfcfq3zq5oof2i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003974; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=89360b4c7415c088&resid=89360b4c7415c088%21108&authkey=amfbkmapqbvzpvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003975; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003976; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003977; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003978; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003979; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003980; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!254&authkey=ajt5wxegbvzbwqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003981; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!255&authkey=aaimhpp89qmcfhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003982; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33%21254&authkey=ajt5wxegbvzbwqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003983; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003984; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003985; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003986; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003987; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003988; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!112&authkey=af43qpcgl0t2f5o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003989; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003990; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003991; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003992; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003993; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003994; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003995; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003996; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003997; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003998; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003999; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004000; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004001; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004002; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004003; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004004; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004005; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004006; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004007; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004008; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004009; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004010; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004011; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004012; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004013; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004014; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004015; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004016; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004017; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004018; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004019; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004020; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004021; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004022; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a31988151cf6813e&resid=a31988151cf6813e%21107&authkey=ab9lanzt1aj_0ws"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004023; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004024; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004025; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004026; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004027; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004028; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004029; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004030; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21256&authkey=aapnly5qifymcvw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004031; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004032; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004033; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004034; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004035; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004036; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004037; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004038; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004039; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004040; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004041; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818!129&authkey=aesewk3cf5vbrxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004042; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818%21129&authkey=aesewk3cf5vbrxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004043; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004044; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004045; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004046; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004047; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004048; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004049; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004050; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004051; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004052; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004053; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004054; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004055; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004056; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004057; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004058; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004059; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004060; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004061; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004062; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004063; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004064; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004065; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004066; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004067; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004068; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004069; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004070; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1047&authkey=aod6jbxyicq2v4g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004071; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211047&authkey=aod6jbxyicq2v4g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004072; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004073; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004074; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004075; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004076; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004077; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004078; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004079; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004080; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004081; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004082; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004083; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004084; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004085; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004086; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004087; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004088; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004089; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004090; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004091; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004092; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004093; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004094; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004095; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004096; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004097; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004098; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004099; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004100; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004101; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004102; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004103; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004104; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004105; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004106; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004107; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004108; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cda6c13b54bbe48c&resid=cda6c13b54bbe48c!44331&authkey=afohia-wo-alwiy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004109; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cda6c13b54bbe48c&resid=cda6c13b54bbe48c%2144331&authkey=afohia-wo-alwiy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004110; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004111; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004112; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004113; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004114; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004115; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004116; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004117; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004118; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004119; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004120; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004121; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d4d413b6e7cf7088&resid=d4d413b6e7cf7088%211271&authkey=akz65bxpgvdxjb8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004122; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004123; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004124; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004125; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004126; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004127; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004128; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004129; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004130; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004131; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004132; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004133; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004134; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004135; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004136; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004137; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2!1818&authkey=anh2wga7qmhbmuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004138; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2%211818&authkey=anh2wga7qmhbmuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004139; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004140; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004141; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004142; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004143; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004144; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004145; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2!107&authkey=af-bicrg1c6vgck"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004146; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2%21107&authkey=af-bicrg1c6vgck"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004147; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004148; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004149; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004150; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004151; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004152; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004153; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004154; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004155; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004156; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004157; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e627fc797baa3032&resid=e627fc797baa3032!2324&authkey=aa8i-r7ixmcraha"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004158; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e627fc797baa3032&resid=e627fc797baa3032%212324&authkey=aa8i-r7ixmcraha"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004159; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004160; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004161; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004162; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004163; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004164; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8!148&authkey=agjcwq650c8wdbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004165; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8!150&authkey=ami5aqoinvosjle"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004166; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8%21148&authkey=agjcwq650c8wdbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004167; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8%21150&authkey=ami5aqoinvosjle"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004168; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004169; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004170; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004171; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004172; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004173; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004174; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004175; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ef7cc06ce7ffafb8&resid=ef7cc06ce7ffafb8%21108&authkey=anmpeqm9gm_zv9m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004176; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004177; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004178; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004179; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004180; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004181; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004182; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004183; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004184; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004185; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004186; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004187; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004188; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004189; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004190; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004191; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004192; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!226&authkey=adho6klfkjflaqk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004193; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!229&authkey=akvo12quxgcwnk8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004194; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!234&authkey=abhyu_zfy6bhwmu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004195; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004196; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21226&authkey=adho6klfkjflaqk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004197; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21234&authkey=abhyu_zfy6bhwmu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004198; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c!115&authkey=adbcrakskolznjq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004199; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c%21115&authkey=adbcrakskolznjq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004200; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c%21116&authkey=anenotuhbsni0zu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004201; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004202; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004203; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004204; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004205; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004206; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004207; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004208; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fd67fafc46d3c687&resid=fd67fafc46d3c687%21473&authkey=aoid_cp-jgffqvm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004209; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004210; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004211; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004212; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21848&authkey=ag1_e421v-t5r9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004213; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004214; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!198&authkey=amg468jpljbyyky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004215; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21198&authkey=amg468jpljbyyky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004216; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004217; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004218; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004219; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004220; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004221; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004222; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004223; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004224; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004225; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004226; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/r/a39ev"; http_uri; nocase; content:"paste.ee"; content:"Host"; http_header; classtype:trojan-activity; sid:100004227; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/77jhk0iw"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004228; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/89hkc7wb"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004229; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/yqvsvlvq"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004230; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/llc/mwcacs65xienqdp/"; http_uri; nocase; content:"pierreconsulting.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004231; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bayesian-forecasting-amj5e/s5hqmf6/"; http_uri; nocase; content:"pioneiraagronegocio.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004232; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skoda22.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004233; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004234; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; http_uri; nocase; content:"qjbutterflyevents.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004235; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dhlshipmentawb80326979402.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004236; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/maersk-bl+draft-copy-shipping-documents.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004237; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/po+for+april+shipment.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004238; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zenar.exe"; http_uri; nocase; content:"racisa.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004239; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004240; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004241; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004242; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004243; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004244; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004245; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/myqseeaccount/one/main/one.htm"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004246; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004247; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004248; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004249; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tennc/webshell/master/other/small_shell.txt"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004250; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; http_uri; nocase; content:"res.yeshen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004251; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/q05z91"; http_uri; nocase; content:"sendspace.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004252; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ey4lpx8rx.zip"; http_uri; nocase; content:"shribharatvatika.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004253; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004254; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004255; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004256; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004257; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004258; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004259; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004260; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004261; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004262; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004263; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/a-nurse-ss8d9/z/"; http_uri; nocase; content:"technologydistilled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004264; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/23.exe"; http_uri; nocase; content:"tsrv4.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100004265; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/crisanar/defis/jek_crackme1.7.zip"; http_uri; nocase; content:"users.skynet.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100004266; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/amowvegfrt9ja/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004267; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004268; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004269; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004270; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004271; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb%5efr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004272; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb^fr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004273; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004274; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/151_155/tidex_-_short_stuff.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004275; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/syria-files/attach/222/222051_instruction.zip"; http_uri; nocase; content:"wikileaks.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004276; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/common/yz.vbs"; http_uri; nocase; content:"yp.hnggzyjy.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004277; rev:1;) diff --git a/urlhaus-filter-snort3-online.rules b/urlhaus-filter-snort3-online.rules index 7dcaf55b..010da56e 100644 --- a/urlhaus-filter-snort3-online.rules +++ b/urlhaus-filter-snort3-online.rules @@ -1,5 +1,5 @@ # Title: Online Malicious URL Snort3 Ruleset -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -7,40 +7,40 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"0-24bpautomentes.hu",nocase; classtype:trojan-activity; sid:100000001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"0cl.sldov.ru",nocase; classtype:trojan-activity; sid:100000002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.11.234.99",nocase; classtype:trojan-activity; sid:100000003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.222.196.60",nocase; classtype:trojan-activity; sid:100000004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.245.4.163",nocase; classtype:trojan-activity; sid:100000005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.107",nocase; classtype:trojan-activity; sid:100000006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.109",nocase; classtype:trojan-activity; sid:100000007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.113",nocase; classtype:trojan-activity; sid:100000008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.127",nocase; classtype:trojan-activity; sid:100000009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.134",nocase; classtype:trojan-activity; sid:100000010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.138",nocase; classtype:trojan-activity; sid:100000011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.14",nocase; classtype:trojan-activity; sid:100000012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.16",nocase; classtype:trojan-activity; sid:100000013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.186.151.219",nocase; classtype:trojan-activity; sid:100000004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.222.196.60",nocase; classtype:trojan-activity; sid:100000005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.245.4.163",nocase; classtype:trojan-activity; sid:100000006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.107",nocase; classtype:trojan-activity; sid:100000007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.109",nocase; classtype:trojan-activity; sid:100000008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.113",nocase; classtype:trojan-activity; sid:100000009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.127",nocase; classtype:trojan-activity; sid:100000010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.134",nocase; classtype:trojan-activity; sid:100000011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.138",nocase; classtype:trojan-activity; sid:100000012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.14",nocase; classtype:trojan-activity; sid:100000013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.165",nocase; classtype:trojan-activity; sid:100000014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.20",nocase; classtype:trojan-activity; sid:100000015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.228",nocase; classtype:trojan-activity; sid:100000016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.232",nocase; classtype:trojan-activity; sid:100000017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.234",nocase; classtype:trojan-activity; sid:100000018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.237",nocase; classtype:trojan-activity; sid:100000019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.245",nocase; classtype:trojan-activity; sid:100000020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.249",nocase; classtype:trojan-activity; sid:100000021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.25",nocase; classtype:trojan-activity; sid:100000022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.38",nocase; classtype:trojan-activity; sid:100000023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.41",nocase; classtype:trojan-activity; sid:100000024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.43",nocase; classtype:trojan-activity; sid:100000025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.45",nocase; classtype:trojan-activity; sid:100000026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.56",nocase; classtype:trojan-activity; sid:100000027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.63",nocase; classtype:trojan-activity; sid:100000028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.69",nocase; classtype:trojan-activity; sid:100000029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.8",nocase; classtype:trojan-activity; sid:100000030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.80",nocase; classtype:trojan-activity; sid:100000031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.94",nocase; classtype:trojan-activity; sid:100000032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.98",nocase; classtype:trojan-activity; sid:100000033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.10",nocase; classtype:trojan-activity; sid:100000034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.103",nocase; classtype:trojan-activity; sid:100000035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.105",nocase; classtype:trojan-activity; sid:100000036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.109",nocase; classtype:trojan-activity; sid:100000037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.234",nocase; classtype:trojan-activity; sid:100000017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.237",nocase; classtype:trojan-activity; sid:100000018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.245",nocase; classtype:trojan-activity; sid:100000019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.249",nocase; classtype:trojan-activity; sid:100000020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.25",nocase; classtype:trojan-activity; sid:100000021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.38",nocase; classtype:trojan-activity; sid:100000022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.41",nocase; classtype:trojan-activity; sid:100000023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.43",nocase; classtype:trojan-activity; sid:100000024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.45",nocase; classtype:trojan-activity; sid:100000025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.56",nocase; classtype:trojan-activity; sid:100000026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.63",nocase; classtype:trojan-activity; sid:100000027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.69",nocase; classtype:trojan-activity; sid:100000028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.8",nocase; classtype:trojan-activity; sid:100000029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.80",nocase; classtype:trojan-activity; sid:100000030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.94",nocase; classtype:trojan-activity; sid:100000031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.98",nocase; classtype:trojan-activity; sid:100000032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.10",nocase; classtype:trojan-activity; sid:100000033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.103",nocase; classtype:trojan-activity; sid:100000034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.105",nocase; classtype:trojan-activity; sid:100000035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.109",nocase; classtype:trojan-activity; sid:100000036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.126",nocase; classtype:trojan-activity; sid:100000037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.127",nocase; classtype:trojan-activity; sid:100000038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.130",nocase; classtype:trojan-activity; sid:100000039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.146",nocase; classtype:trojan-activity; sid:100000040; rev:1;) @@ -78,4328 +78,4206 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.73.131.78",nocase; classtype:trojan-activity; sid:100000072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.75.157.99",nocase; classtype:trojan-activity; sid:100000073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.75.167.213",nocase; classtype:trojan-activity; sid:100000074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.99.94.15",nocase; classtype:trojan-activity; sid:100000075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.130.115.14",nocase; classtype:trojan-activity; sid:100000076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.141.240.139",nocase; classtype:trojan-activity; sid:100000077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.113.99.79",nocase; classtype:trojan-activity; sid:100000078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.125.218.107",nocase; classtype:trojan-activity; sid:100000079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.136.82.50",nocase; classtype:trojan-activity; sid:100000080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.141.138.118",nocase; classtype:trojan-activity; sid:100000081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.141.138.12",nocase; classtype:trojan-activity; sid:100000082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.146.174.208",nocase; classtype:trojan-activity; sid:100000083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.16.145.25",nocase; classtype:trojan-activity; sid:100000084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.204.168.34",nocase; classtype:trojan-activity; sid:100000085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.217.215.21",nocase; classtype:trojan-activity; sid:100000086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.224.200.146",nocase; classtype:trojan-activity; sid:100000087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.224.200.40",nocase; classtype:trojan-activity; sid:100000088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.227.118.129",nocase; classtype:trojan-activity; sid:100000089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.238.228.4",nocase; classtype:trojan-activity; sid:100000090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.240.249.121",nocase; classtype:trojan-activity; sid:100000091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.4.117.26",nocase; classtype:trojan-activity; sid:100000092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.70.160.51",nocase; classtype:trojan-activity; sid:100000093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.79.112.254",nocase; classtype:trojan-activity; sid:100000094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.82.98.170",nocase; classtype:trojan-activity; sid:100000095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.240.130",nocase; classtype:trojan-activity; sid:100000096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.12",nocase; classtype:trojan-activity; sid:100000097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.13",nocase; classtype:trojan-activity; sid:100000098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.14",nocase; classtype:trojan-activity; sid:100000099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.16",nocase; classtype:trojan-activity; sid:100000100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.17",nocase; classtype:trojan-activity; sid:100000101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.27",nocase; classtype:trojan-activity; sid:100000102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.3",nocase; classtype:trojan-activity; sid:100000103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.46",nocase; classtype:trojan-activity; sid:100000104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.90",nocase; classtype:trojan-activity; sid:100000105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.95",nocase; classtype:trojan-activity; sid:100000106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.97.184.180",nocase; classtype:trojan-activity; sid:100000107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.168.98.159",nocase; classtype:trojan-activity; sid:100000108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.184.75.123",nocase; classtype:trojan-activity; sid:100000109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.206.93.94",nocase; classtype:trojan-activity; sid:100000110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.33.52.85",nocase; classtype:trojan-activity; sid:100000111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.61.86.37",nocase; classtype:trojan-activity; sid:100000112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.1.111.91",nocase; classtype:trojan-activity; sid:100000113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.104.172.178",nocase; classtype:trojan-activity; sid:100000114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.104.193.155",nocase; classtype:trojan-activity; sid:100000115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.105.33.43",nocase; classtype:trojan-activity; sid:100000116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.165.234",nocase; classtype:trojan-activity; sid:100000117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.193.132",nocase; classtype:trojan-activity; sid:100000118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.249.148",nocase; classtype:trojan-activity; sid:100000119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.155.54",nocase; classtype:trojan-activity; sid:100000120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.219.80",nocase; classtype:trojan-activity; sid:100000121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.250.107",nocase; classtype:trojan-activity; sid:100000122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.61.139",nocase; classtype:trojan-activity; sid:100000123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.197.135",nocase; classtype:trojan-activity; sid:100000124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.31.130",nocase; classtype:trojan-activity; sid:100000125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.33.48",nocase; classtype:trojan-activity; sid:100000126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.181.136.96",nocase; classtype:trojan-activity; sid:100000127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.189.8.75",nocase; classtype:trojan-activity; sid:100000128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.194.242.170",nocase; classtype:trojan-activity; sid:100000129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.219.185.75",nocase; classtype:trojan-activity; sid:100000130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.220.119.25",nocase; classtype:trojan-activity; sid:100000131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.221.96.202",nocase; classtype:trojan-activity; sid:100000132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.201.37",nocase; classtype:trojan-activity; sid:100000133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.250.48",nocase; classtype:trojan-activity; sid:100000134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.55.199.65",nocase; classtype:trojan-activity; sid:100000135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.124.90.229",nocase; classtype:trojan-activity; sid:100000136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.233.196.232",nocase; classtype:trojan-activity; sid:100000137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.235.7.228",nocase; classtype:trojan-activity; sid:100000138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.86.85.253",nocase; classtype:trojan-activity; sid:100000139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.102",nocase; classtype:trojan-activity; sid:100000140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.230",nocase; classtype:trojan-activity; sid:100000141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.127.90",nocase; classtype:trojan-activity; sid:100000142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.57.246",nocase; classtype:trojan-activity; sid:100000143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.99.37.97",nocase; classtype:trojan-activity; sid:100000144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.10.58.38",nocase; classtype:trojan-activity; sid:100000145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.14.58.190",nocase; classtype:trojan-activity; sid:100000146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.187.229.182",nocase; classtype:trojan-activity; sid:100000147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.228.190.50",nocase; classtype:trojan-activity; sid:100000148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.228.195.46",nocase; classtype:trojan-activity; sid:100000149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.241.119.168",nocase; classtype:trojan-activity; sid:100000150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.124.254",nocase; classtype:trojan-activity; sid:100000151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.251.194",nocase; classtype:trojan-activity; sid:100000152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.251.10.18",nocase; classtype:trojan-activity; sid:100000153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.150.248",nocase; classtype:trojan-activity; sid:100000154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.213.198",nocase; classtype:trojan-activity; sid:100000155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.130.115.14",nocase; classtype:trojan-activity; sid:100000075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.141.240.139",nocase; classtype:trojan-activity; sid:100000076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.113.99.79",nocase; classtype:trojan-activity; sid:100000077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.125.218.107",nocase; classtype:trojan-activity; sid:100000078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.141.138.118",nocase; classtype:trojan-activity; sid:100000079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.141.138.12",nocase; classtype:trojan-activity; sid:100000080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.146.174.208",nocase; classtype:trojan-activity; sid:100000081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.16.145.25",nocase; classtype:trojan-activity; sid:100000082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.204.168.34",nocase; classtype:trojan-activity; sid:100000083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.217.215.21",nocase; classtype:trojan-activity; sid:100000084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.224.200.146",nocase; classtype:trojan-activity; sid:100000085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.224.200.40",nocase; classtype:trojan-activity; sid:100000086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.237.21.36",nocase; classtype:trojan-activity; sid:100000087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.238.228.4",nocase; classtype:trojan-activity; sid:100000088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.240.249.121",nocase; classtype:trojan-activity; sid:100000089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.4.117.26",nocase; classtype:trojan-activity; sid:100000090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.70.160.51",nocase; classtype:trojan-activity; sid:100000091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.82.98.170",nocase; classtype:trojan-activity; sid:100000092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.240.130",nocase; classtype:trojan-activity; sid:100000093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.12",nocase; classtype:trojan-activity; sid:100000094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.13",nocase; classtype:trojan-activity; sid:100000095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.14",nocase; classtype:trojan-activity; sid:100000096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.16",nocase; classtype:trojan-activity; sid:100000097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.17",nocase; classtype:trojan-activity; sid:100000098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.27",nocase; classtype:trojan-activity; sid:100000099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.3",nocase; classtype:trojan-activity; sid:100000100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.46",nocase; classtype:trojan-activity; sid:100000101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.90",nocase; classtype:trojan-activity; sid:100000102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.95",nocase; classtype:trojan-activity; sid:100000103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.97.184.180",nocase; classtype:trojan-activity; sid:100000104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.168.98.159",nocase; classtype:trojan-activity; sid:100000105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.184.75.123",nocase; classtype:trojan-activity; sid:100000106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.206.93.94",nocase; classtype:trojan-activity; sid:100000107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.33.52.85",nocase; classtype:trojan-activity; sid:100000108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.61.86.37",nocase; classtype:trojan-activity; sid:100000109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.1.111.91",nocase; classtype:trojan-activity; sid:100000110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.104.172.178",nocase; classtype:trojan-activity; sid:100000111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.104.193.155",nocase; classtype:trojan-activity; sid:100000112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.105.33.43",nocase; classtype:trojan-activity; sid:100000113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.165.234",nocase; classtype:trojan-activity; sid:100000114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.193.132",nocase; classtype:trojan-activity; sid:100000115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.249.148",nocase; classtype:trojan-activity; sid:100000116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.155.54",nocase; classtype:trojan-activity; sid:100000117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.219.80",nocase; classtype:trojan-activity; sid:100000118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.250.107",nocase; classtype:trojan-activity; sid:100000119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.61.139",nocase; classtype:trojan-activity; sid:100000120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.197.135",nocase; classtype:trojan-activity; sid:100000121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.31.130",nocase; classtype:trojan-activity; sid:100000122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.33.48",nocase; classtype:trojan-activity; sid:100000123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.181.136.96",nocase; classtype:trojan-activity; sid:100000124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.189.8.75",nocase; classtype:trojan-activity; sid:100000125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.194.242.170",nocase; classtype:trojan-activity; sid:100000126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.219.185.75",nocase; classtype:trojan-activity; sid:100000127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.220.119.25",nocase; classtype:trojan-activity; sid:100000128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.221.96.202",nocase; classtype:trojan-activity; sid:100000129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.201.37",nocase; classtype:trojan-activity; sid:100000130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.250.48",nocase; classtype:trojan-activity; sid:100000131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.55.199.65",nocase; classtype:trojan-activity; sid:100000132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.124.90.229",nocase; classtype:trojan-activity; sid:100000133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.233.196.232",nocase; classtype:trojan-activity; sid:100000134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.235.7.228",nocase; classtype:trojan-activity; sid:100000135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.248.58.238",nocase; classtype:trojan-activity; sid:100000136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.86.85.253",nocase; classtype:trojan-activity; sid:100000137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.102",nocase; classtype:trojan-activity; sid:100000138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.230",nocase; classtype:trojan-activity; sid:100000139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.127.90",nocase; classtype:trojan-activity; sid:100000140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.57.246",nocase; classtype:trojan-activity; sid:100000141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.99.37.97",nocase; classtype:trojan-activity; sid:100000142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.10.58.38",nocase; classtype:trojan-activity; sid:100000143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.14.58.190",nocase; classtype:trojan-activity; sid:100000144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.187.229.182",nocase; classtype:trojan-activity; sid:100000145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.228.190.50",nocase; classtype:trojan-activity; sid:100000146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.228.195.46",nocase; classtype:trojan-activity; sid:100000147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.241.119.168",nocase; classtype:trojan-activity; sid:100000148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.124.254",nocase; classtype:trojan-activity; sid:100000149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.175.141",nocase; classtype:trojan-activity; sid:100000150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.251.194",nocase; classtype:trojan-activity; sid:100000151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.251.10.18",nocase; classtype:trojan-activity; sid:100000152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.150.248",nocase; classtype:trojan-activity; sid:100000153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.213.198",nocase; classtype:trojan-activity; sid:100000154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.51.112",nocase; classtype:trojan-activity; sid:100000155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.255.101.184",nocase; classtype:trojan-activity; sid:100000156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.255.167.147",nocase; classtype:trojan-activity; sid:100000157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.145.127",nocase; classtype:trojan-activity; sid:100000158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.208.21",nocase; classtype:trojan-activity; sid:100000159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.221.77",nocase; classtype:trojan-activity; sid:100000160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.223.92",nocase; classtype:trojan-activity; sid:100000161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.225.24",nocase; classtype:trojan-activity; sid:100000162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.233.147",nocase; classtype:trojan-activity; sid:100000163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.235.57",nocase; classtype:trojan-activity; sid:100000164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.4.2",nocase; classtype:trojan-activity; sid:100000165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110fss.net",nocase; classtype:trojan-activity; sid:100000166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.111.207",nocase; classtype:trojan-activity; sid:100000167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.41.173",nocase; classtype:trojan-activity; sid:100000168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.88.61",nocase; classtype:trojan-activity; sid:100000169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.119.245.114",nocase; classtype:trojan-activity; sid:100000170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.125.67.125",nocase; classtype:trojan-activity; sid:100000171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.165.21.195",nocase; classtype:trojan-activity; sid:100000172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.165.248.134",nocase; classtype:trojan-activity; sid:100000173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.166.236.191",nocase; classtype:trojan-activity; sid:100000174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.167.151.156",nocase; classtype:trojan-activity; sid:100000175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.85.71",nocase; classtype:trojan-activity; sid:100000176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.86.31",nocase; classtype:trojan-activity; sid:100000177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.172.57.20",nocase; classtype:trojan-activity; sid:100000178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.182.235.252",nocase; classtype:trojan-activity; sid:100000179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.171.111",nocase; classtype:trojan-activity; sid:100000180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.177.85",nocase; classtype:trojan-activity; sid:100000181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.23.84",nocase; classtype:trojan-activity; sid:100000182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.230.136",nocase; classtype:trojan-activity; sid:100000183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.27.9",nocase; classtype:trojan-activity; sid:100000184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.49.223",nocase; classtype:trojan-activity; sid:100000185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.122",nocase; classtype:trojan-activity; sid:100000186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.66",nocase; classtype:trojan-activity; sid:100000187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.104.141",nocase; classtype:trojan-activity; sid:100000188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.104.15",nocase; classtype:trojan-activity; sid:100000189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.128",nocase; classtype:trojan-activity; sid:100000190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.19",nocase; classtype:trojan-activity; sid:100000191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.222",nocase; classtype:trojan-activity; sid:100000192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.223",nocase; classtype:trojan-activity; sid:100000193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.226",nocase; classtype:trojan-activity; sid:100000194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.228",nocase; classtype:trojan-activity; sid:100000195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.26.243",nocase; classtype:trojan-activity; sid:100000196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.61.52.53",nocase; classtype:trojan-activity; sid:100000197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.108.184",nocase; classtype:trojan-activity; sid:100000198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.31.175",nocase; classtype:trojan-activity; sid:100000199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.133.222.151",nocase; classtype:trojan-activity; sid:100000200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.147.92.51",nocase; classtype:trojan-activity; sid:100000201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.159.108.96",nocase; classtype:trojan-activity; sid:100000202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.163.200.217",nocase; classtype:trojan-activity; sid:100000203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.124.75",nocase; classtype:trojan-activity; sid:100000204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.233.9",nocase; classtype:trojan-activity; sid:100000205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.210.211",nocase; classtype:trojan-activity; sid:100000206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.96.252",nocase; classtype:trojan-activity; sid:100000207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.187.91.117",nocase; classtype:trojan-activity; sid:100000208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.214.127.42",nocase; classtype:trojan-activity; sid:100000209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.187.19",nocase; classtype:trojan-activity; sid:100000210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.236.77",nocase; classtype:trojan-activity; sid:100000211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.239.126",nocase; classtype:trojan-activity; sid:100000212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.43.27",nocase; classtype:trojan-activity; sid:100000213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.118.229",nocase; classtype:trojan-activity; sid:100000214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.202.111",nocase; classtype:trojan-activity; sid:100000215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.67.193",nocase; classtype:trojan-activity; sid:100000216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.180.95",nocase; classtype:trojan-activity; sid:100000217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.79.114",nocase; classtype:trojan-activity; sid:100000218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.79.137",nocase; classtype:trojan-activity; sid:100000219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.178.109",nocase; classtype:trojan-activity; sid:100000220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.188.28",nocase; classtype:trojan-activity; sid:100000221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.230.168.103",nocase; classtype:trojan-activity; sid:100000222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.218.202",nocase; classtype:trojan-activity; sid:100000223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.235.149.73",nocase; classtype:trojan-activity; sid:100000224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.235.188.86",nocase; classtype:trojan-activity; sid:100000225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.171.69",nocase; classtype:trojan-activity; sid:100000226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.141.241",nocase; classtype:trojan-activity; sid:100000227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.144.226",nocase; classtype:trojan-activity; sid:100000228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.197.144",nocase; classtype:trojan-activity; sid:100000229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.209.30",nocase; classtype:trojan-activity; sid:100000230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.75.157",nocase; classtype:trojan-activity; sid:100000231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.143.135",nocase; classtype:trojan-activity; sid:100000232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.17.120",nocase; classtype:trojan-activity; sid:100000233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.190.207",nocase; classtype:trojan-activity; sid:100000234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.227.228",nocase; classtype:trojan-activity; sid:100000235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.39.2",nocase; classtype:trojan-activity; sid:100000236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.73.181",nocase; classtype:trojan-activity; sid:100000237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.240.216.17",nocase; classtype:trojan-activity; sid:100000238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.152.44",nocase; classtype:trojan-activity; sid:100000239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.2.247",nocase; classtype:trojan-activity; sid:100000240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.243.80",nocase; classtype:trojan-activity; sid:100000241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.12.89",nocase; classtype:trojan-activity; sid:100000242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.8.24",nocase; classtype:trojan-activity; sid:100000243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.126.58",nocase; classtype:trojan-activity; sid:100000244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.162.50",nocase; classtype:trojan-activity; sid:100000245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.180.49",nocase; classtype:trojan-activity; sid:100000246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.51.77",nocase; classtype:trojan-activity; sid:100000247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.100.14",nocase; classtype:trojan-activity; sid:100000248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.121.39",nocase; classtype:trojan-activity; sid:100000249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.16.222",nocase; classtype:trojan-activity; sid:100000250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.191.118",nocase; classtype:trojan-activity; sid:100000251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.214.146",nocase; classtype:trojan-activity; sid:100000252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.240.226",nocase; classtype:trojan-activity; sid:100000253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.25.42",nocase; classtype:trojan-activity; sid:100000254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.8.112",nocase; classtype:trojan-activity; sid:100000255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.81.173",nocase; classtype:trojan-activity; sid:100000256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.82.122",nocase; classtype:trojan-activity; sid:100000257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.148.90",nocase; classtype:trojan-activity; sid:100000258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.179.239",nocase; classtype:trojan-activity; sid:100000259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.197.164",nocase; classtype:trojan-activity; sid:100000260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.109.217",nocase; classtype:trojan-activity; sid:100000261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.118.157",nocase; classtype:trojan-activity; sid:100000262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.26.129",nocase; classtype:trojan-activity; sid:100000263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.79.98",nocase; classtype:trojan-activity; sid:100000264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.250.102.173",nocase; classtype:trojan-activity; sid:100000265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.250.57.99",nocase; classtype:trojan-activity; sid:100000266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.218.210",nocase; classtype:trojan-activity; sid:100000267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.136.84",nocase; classtype:trojan-activity; sid:100000268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.196.17",nocase; classtype:trojan-activity; sid:100000269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.212.122",nocase; classtype:trojan-activity; sid:100000270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.221.244",nocase; classtype:trojan-activity; sid:100000271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.239.103",nocase; classtype:trojan-activity; sid:100000272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.254.208.123",nocase; classtype:trojan-activity; sid:100000273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.254.32.5",nocase; classtype:trojan-activity; sid:100000274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.38.10",nocase; classtype:trojan-activity; sid:100000275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.6.129",nocase; classtype:trojan-activity; sid:100000276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.8.235",nocase; classtype:trojan-activity; sid:100000277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.121.163",nocase; classtype:trojan-activity; sid:100000278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.108",nocase; classtype:trojan-activity; sid:100000279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.111",nocase; classtype:trojan-activity; sid:100000280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.117",nocase; classtype:trojan-activity; sid:100000281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.122",nocase; classtype:trojan-activity; sid:100000282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.124",nocase; classtype:trojan-activity; sid:100000283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.131",nocase; classtype:trojan-activity; sid:100000284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.132",nocase; classtype:trojan-activity; sid:100000285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.133",nocase; classtype:trojan-activity; sid:100000286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.138",nocase; classtype:trojan-activity; sid:100000287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.139",nocase; classtype:trojan-activity; sid:100000288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.142",nocase; classtype:trojan-activity; sid:100000289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.143",nocase; classtype:trojan-activity; sid:100000290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.146",nocase; classtype:trojan-activity; sid:100000291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.149",nocase; classtype:trojan-activity; sid:100000292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.150",nocase; classtype:trojan-activity; sid:100000293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.151",nocase; classtype:trojan-activity; sid:100000294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.158",nocase; classtype:trojan-activity; sid:100000295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.160",nocase; classtype:trojan-activity; sid:100000296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.162",nocase; classtype:trojan-activity; sid:100000297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.163",nocase; classtype:trojan-activity; sid:100000298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.165",nocase; classtype:trojan-activity; sid:100000299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.171",nocase; classtype:trojan-activity; sid:100000300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.174",nocase; classtype:trojan-activity; sid:100000301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.175",nocase; classtype:trojan-activity; sid:100000302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.177",nocase; classtype:trojan-activity; sid:100000303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.178",nocase; classtype:trojan-activity; sid:100000304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.179",nocase; classtype:trojan-activity; sid:100000305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.71",nocase; classtype:trojan-activity; sid:100000306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.127.155",nocase; classtype:trojan-activity; sid:100000307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.182",nocase; classtype:trojan-activity; sid:100000308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.23",nocase; classtype:trojan-activity; sid:100000309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.85.113",nocase; classtype:trojan-activity; sid:100000310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.87.213",nocase; classtype:trojan-activity; sid:100000311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.88.116",nocase; classtype:trojan-activity; sid:100000312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.91.212",nocase; classtype:trojan-activity; sid:100000313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.133",nocase; classtype:trojan-activity; sid:100000314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.158",nocase; classtype:trojan-activity; sid:100000315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.164",nocase; classtype:trojan-activity; sid:100000316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.168",nocase; classtype:trojan-activity; sid:100000317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.177",nocase; classtype:trojan-activity; sid:100000318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.188",nocase; classtype:trojan-activity; sid:100000319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.190",nocase; classtype:trojan-activity; sid:100000320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.211",nocase; classtype:trojan-activity; sid:100000321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.219",nocase; classtype:trojan-activity; sid:100000322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.229",nocase; classtype:trojan-activity; sid:100000323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.230",nocase; classtype:trojan-activity; sid:100000324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.247",nocase; classtype:trojan-activity; sid:100000325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.57",nocase; classtype:trojan-activity; sid:100000326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.90",nocase; classtype:trojan-activity; sid:100000327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.91",nocase; classtype:trojan-activity; sid:100000328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.31",nocase; classtype:trojan-activity; sid:100000329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.36",nocase; classtype:trojan-activity; sid:100000330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.37",nocase; classtype:trojan-activity; sid:100000331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.38",nocase; classtype:trojan-activity; sid:100000332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.41",nocase; classtype:trojan-activity; sid:100000333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.43",nocase; classtype:trojan-activity; sid:100000334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.48",nocase; classtype:trojan-activity; sid:100000335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.52",nocase; classtype:trojan-activity; sid:100000336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.35.237",nocase; classtype:trojan-activity; sid:100000337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.38.98",nocase; classtype:trojan-activity; sid:100000338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.103",nocase; classtype:trojan-activity; sid:100000339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.118",nocase; classtype:trojan-activity; sid:100000340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.121",nocase; classtype:trojan-activity; sid:100000341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.124",nocase; classtype:trojan-activity; sid:100000342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.136",nocase; classtype:trojan-activity; sid:100000343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.52",nocase; classtype:trojan-activity; sid:100000344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.240.239",nocase; classtype:trojan-activity; sid:100000345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.82.160",nocase; classtype:trojan-activity; sid:100000346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.87.98",nocase; classtype:trojan-activity; sid:100000347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.224.79",nocase; classtype:trojan-activity; sid:100000348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.65.53.175",nocase; classtype:trojan-activity; sid:100000349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.49",nocase; classtype:trojan-activity; sid:100000350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.53",nocase; classtype:trojan-activity; sid:100000351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.112",nocase; classtype:trojan-activity; sid:100000352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.84",nocase; classtype:trojan-activity; sid:100000353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.231.35",nocase; classtype:trojan-activity; sid:100000354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.78.45.158",nocase; classtype:trojan-activity; sid:100000355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.117.32",nocase; classtype:trojan-activity; sid:100000356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.118.16",nocase; classtype:trojan-activity; sid:100000357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.127.91",nocase; classtype:trojan-activity; sid:100000358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.207.144",nocase; classtype:trojan-activity; sid:100000359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.215.101",nocase; classtype:trojan-activity; sid:100000360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.146.253",nocase; classtype:trojan-activity; sid:100000361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.18.255",nocase; classtype:trojan-activity; sid:100000362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.224.139",nocase; classtype:trojan-activity; sid:100000363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.93.29.211",nocase; classtype:trojan-activity; sid:100000364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.11.95.254",nocase; classtype:trojan-activity; sid:100000365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.144.140",nocase; classtype:trojan-activity; sid:100000366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.122.238.68",nocase; classtype:trojan-activity; sid:100000367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.161.58.249",nocase; classtype:trojan-activity; sid:100000368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.161.78.185",nocase; classtype:trojan-activity; sid:100000369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.172.250.35",nocase; classtype:trojan-activity; sid:100000370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.195.163.26",nocase; classtype:trojan-activity; sid:100000371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.226.42.250",nocase; classtype:trojan-activity; sid:100000372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.194.172",nocase; classtype:trojan-activity; sid:100000373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.35.229",nocase; classtype:trojan-activity; sid:100000374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.211.131",nocase; classtype:trojan-activity; sid:100000375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.254.169.251",nocase; classtype:trojan-activity; sid:100000376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.128.133",nocase; classtype:trojan-activity; sid:100000377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.136.39",nocase; classtype:trojan-activity; sid:100000378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.154.21",nocase; classtype:trojan-activity; sid:100000379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.191.47",nocase; classtype:trojan-activity; sid:100000380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.61.204.205",nocase; classtype:trojan-activity; sid:100000381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.87.174.63",nocase; classtype:trojan-activity; sid:100000382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.87.175.135",nocase; classtype:trojan-activity; sid:100000383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.89.42.50",nocase; classtype:trojan-activity; sid:100000384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.89.43.185",nocase; classtype:trojan-activity; sid:100000385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.90.26.136",nocase; classtype:trojan-activity; sid:100000386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.199.204.37",nocase; classtype:trojan-activity; sid:100000387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.200.154.181",nocase; classtype:trojan-activity; sid:100000388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.224.203.128",nocase; classtype:trojan-activity; sid:100000389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.226.100.56",nocase; classtype:trojan-activity; sid:100000390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.228.205.101",nocase; classtype:trojan-activity; sid:100000391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.229.165.194",nocase; classtype:trojan-activity; sid:100000392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.235.115.236",nocase; classtype:trojan-activity; sid:100000393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.30.54.64",nocase; classtype:trojan-activity; sid:100000394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.32.237.100",nocase; classtype:trojan-activity; sid:100000395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.79.172.42",nocase; classtype:trojan-activity; sid:100000396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.165.216.112",nocase; classtype:trojan-activity; sid:100000397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.201.38.185",nocase; classtype:trojan-activity; sid:100000398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.42.47.36",nocase; classtype:trojan-activity; sid:100000399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.204.56",nocase; classtype:trojan-activity; sid:100000400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.21.56",nocase; classtype:trojan-activity; sid:100000401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.125.55",nocase; classtype:trojan-activity; sid:100000402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.18.65",nocase; classtype:trojan-activity; sid:100000403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.144.42",nocase; classtype:trojan-activity; sid:100000404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.145.147",nocase; classtype:trojan-activity; sid:100000405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.153.194",nocase; classtype:trojan-activity; sid:100000406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.190.144",nocase; classtype:trojan-activity; sid:100000407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.60.129",nocase; classtype:trojan-activity; sid:100000408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.131.242",nocase; classtype:trojan-activity; sid:100000409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.133.96",nocase; classtype:trojan-activity; sid:100000410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.144.213",nocase; classtype:trojan-activity; sid:100000411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.159.132",nocase; classtype:trojan-activity; sid:100000412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.187.173",nocase; classtype:trojan-activity; sid:100000413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.132.140",nocase; classtype:trojan-activity; sid:100000414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.165.147",nocase; classtype:trojan-activity; sid:100000415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.240.217",nocase; classtype:trojan-activity; sid:100000416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.255.194",nocase; classtype:trojan-activity; sid:100000417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.118.201",nocase; classtype:trojan-activity; sid:100000418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.62.26.39",nocase; classtype:trojan-activity; sid:100000419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.73.3.11",nocase; classtype:trojan-activity; sid:100000420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.92.174.231",nocase; classtype:trojan-activity; sid:100000421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.124.219.2",nocase; classtype:trojan-activity; sid:100000422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.132.151.60",nocase; classtype:trojan-activity; sid:100000423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.206.164.46",nocase; classtype:trojan-activity; sid:100000424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.211.100.26",nocase; classtype:trojan-activity; sid:100000425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.212.132.119",nocase; classtype:trojan-activity; sid:100000426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.212.142.215",nocase; classtype:trojan-activity; sid:100000427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.196.49.249",nocase; classtype:trojan-activity; sid:100000428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.196.50.107",nocase; classtype:trojan-activity; sid:100000429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.138",nocase; classtype:trojan-activity; sid:100000430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.5",nocase; classtype:trojan-activity; sid:100000431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.210.52",nocase; classtype:trojan-activity; sid:100000432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.236.14",nocase; classtype:trojan-activity; sid:100000433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.243.40",nocase; classtype:trojan-activity; sid:100000434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.200.76.54",nocase; classtype:trojan-activity; sid:100000435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.26.110.103",nocase; classtype:trojan-activity; sid:100000436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.113.146",nocase; classtype:trojan-activity; sid:100000437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.195.140",nocase; classtype:trojan-activity; sid:100000438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.53.15",nocase; classtype:trojan-activity; sid:100000439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.86.105.110",nocase; classtype:trojan-activity; sid:100000440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.104.35",nocase; classtype:trojan-activity; sid:100000441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.157.64",nocase; classtype:trojan-activity; sid:100000442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.7.132",nocase; classtype:trojan-activity; sid:100000443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.32.74",nocase; classtype:trojan-activity; sid:100000444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.5.149",nocase; classtype:trojan-activity; sid:100000445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.72.141",nocase; classtype:trojan-activity; sid:100000446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.12.130",nocase; classtype:trojan-activity; sid:100000447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.128.147",nocase; classtype:trojan-activity; sid:100000448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.208.215",nocase; classtype:trojan-activity; sid:100000449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.209.108",nocase; classtype:trojan-activity; sid:100000450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.214.72",nocase; classtype:trojan-activity; sid:100000451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.88.146",nocase; classtype:trojan-activity; sid:100000452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.150",nocase; classtype:trojan-activity; sid:100000453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.6",nocase; classtype:trojan-activity; sid:100000454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.221.162",nocase; classtype:trojan-activity; sid:100000455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.63.194",nocase; classtype:trojan-activity; sid:100000456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.65.93",nocase; classtype:trojan-activity; sid:100000457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.42.125.246",nocase; classtype:trojan-activity; sid:100000458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.43.180.33",nocase; classtype:trojan-activity; sid:100000459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.125.92",nocase; classtype:trojan-activity; sid:100000460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.218.157",nocase; classtype:trojan-activity; sid:100000461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.50.203",nocase; classtype:trojan-activity; sid:100000462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.58.82",nocase; classtype:trojan-activity; sid:100000463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.96.11",nocase; classtype:trojan-activity; sid:100000464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.83.79.43",nocase; classtype:trojan-activity; sid:100000465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.91.24.27",nocase; classtype:trojan-activity; sid:100000466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.179.164",nocase; classtype:trojan-activity; sid:100000467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.183.235",nocase; classtype:trojan-activity; sid:100000468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.239.217",nocase; classtype:trojan-activity; sid:100000469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.108.161.25",nocase; classtype:trojan-activity; sid:100000470; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.112.185.232",nocase; classtype:trojan-activity; sid:100000471; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.119.63.145",nocase; classtype:trojan-activity; sid:100000472; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.14.143.145",nocase; classtype:trojan-activity; sid:100000473; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.147.213.57",nocase; classtype:trojan-activity; sid:100000474; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.163.93.191",nocase; classtype:trojan-activity; sid:100000475; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.18.235",nocase; classtype:trojan-activity; sid:100000476; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.218.229",nocase; classtype:trojan-activity; sid:100000477; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.107.93",nocase; classtype:trojan-activity; sid:100000478; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.163.220",nocase; classtype:trojan-activity; sid:100000479; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.174.63",nocase; classtype:trojan-activity; sid:100000480; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.197.106",nocase; classtype:trojan-activity; sid:100000481; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.241.222",nocase; classtype:trojan-activity; sid:100000482; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.27.77",nocase; classtype:trojan-activity; sid:100000483; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.68.145",nocase; classtype:trojan-activity; sid:100000484; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.170.241",nocase; classtype:trojan-activity; sid:100000485; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.97.6",nocase; classtype:trojan-activity; sid:100000486; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.26.33",nocase; classtype:trojan-activity; sid:100000487; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.177.147.38",nocase; classtype:trojan-activity; sid:100000488; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.248.123",nocase; classtype:trojan-activity; sid:100000489; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.157.219",nocase; classtype:trojan-activity; sid:100000490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.16.149",nocase; classtype:trojan-activity; sid:100000491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.170.212",nocase; classtype:trojan-activity; sid:100000492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.43.1",nocase; classtype:trojan-activity; sid:100000493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.75.8",nocase; classtype:trojan-activity; sid:100000494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.18.38.144",nocase; classtype:trojan-activity; sid:100000495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.106.217",nocase; classtype:trojan-activity; sid:100000496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.108.227",nocase; classtype:trojan-activity; sid:100000497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.108.79",nocase; classtype:trojan-activity; sid:100000498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.33.161",nocase; classtype:trojan-activity; sid:100000499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.94.80",nocase; classtype:trojan-activity; sid:100000500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.119.21",nocase; classtype:trojan-activity; sid:100000501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.124.203",nocase; classtype:trojan-activity; sid:100000502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.182.97.232",nocase; classtype:trojan-activity; sid:100000503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.183.115.103",nocase; classtype:trojan-activity; sid:100000504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.14.112",nocase; classtype:trojan-activity; sid:100000505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.172.199",nocase; classtype:trojan-activity; sid:100000506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.195.161",nocase; classtype:trojan-activity; sid:100000507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.245.61",nocase; classtype:trojan-activity; sid:100000508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.137.195",nocase; classtype:trojan-activity; sid:100000509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.227.244",nocase; classtype:trojan-activity; sid:100000510; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.150.85",nocase; classtype:trojan-activity; sid:100000511; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.187.206",nocase; classtype:trojan-activity; sid:100000512; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.215.221",nocase; classtype:trojan-activity; sid:100000513; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.240.20",nocase; classtype:trojan-activity; sid:100000514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.204.30.144",nocase; classtype:trojan-activity; sid:100000515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.250.129.231",nocase; classtype:trojan-activity; sid:100000516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.105.221",nocase; classtype:trojan-activity; sid:100000517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.14.251",nocase; classtype:trojan-activity; sid:100000518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.131.155",nocase; classtype:trojan-activity; sid:100000519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.46",nocase; classtype:trojan-activity; sid:100000520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.71",nocase; classtype:trojan-activity; sid:100000521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.144.75",nocase; classtype:trojan-activity; sid:100000522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.148.115",nocase; classtype:trojan-activity; sid:100000523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.155.57",nocase; classtype:trojan-activity; sid:100000524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.172.28",nocase; classtype:trojan-activity; sid:100000525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.175.41",nocase; classtype:trojan-activity; sid:100000526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.195.90",nocase; classtype:trojan-activity; sid:100000527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.206.43",nocase; classtype:trojan-activity; sid:100000528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.232.62",nocase; classtype:trojan-activity; sid:100000529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.132.113.2",nocase; classtype:trojan-activity; sid:100000530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.15.69.83",nocase; classtype:trojan-activity; sid:100000531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.6",nocase; classtype:trojan-activity; sid:100000532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.7",nocase; classtype:trojan-activity; sid:100000533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.8",nocase; classtype:trojan-activity; sid:100000534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.9",nocase; classtype:trojan-activity; sid:100000535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.207.39.227",nocase; classtype:trojan-activity; sid:100000536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.25.204.189",nocase; classtype:trojan-activity; sid:100000537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.0.255.173",nocase; classtype:trojan-activity; sid:100000538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.12.153.54",nocase; classtype:trojan-activity; sid:100000539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.142.222.22",nocase; classtype:trojan-activity; sid:100000540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.150.213.110",nocase; classtype:trojan-activity; sid:100000541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.151.248.134",nocase; classtype:trojan-activity; sid:100000542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.180",nocase; classtype:trojan-activity; sid:100000543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.183",nocase; classtype:trojan-activity; sid:100000544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.185",nocase; classtype:trojan-activity; sid:100000545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.186",nocase; classtype:trojan-activity; sid:100000546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.188",nocase; classtype:trojan-activity; sid:100000547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.193",nocase; classtype:trojan-activity; sid:100000548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.201",nocase; classtype:trojan-activity; sid:100000549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.204",nocase; classtype:trojan-activity; sid:100000550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.208",nocase; classtype:trojan-activity; sid:100000551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.209",nocase; classtype:trojan-activity; sid:100000552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.212",nocase; classtype:trojan-activity; sid:100000553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.215",nocase; classtype:trojan-activity; sid:100000554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.233",nocase; classtype:trojan-activity; sid:100000555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.121.243",nocase; classtype:trojan-activity; sid:100000556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.206",nocase; classtype:trojan-activity; sid:100000557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.240",nocase; classtype:trojan-activity; sid:100000558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.127.187",nocase; classtype:trojan-activity; sid:100000559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.99.127",nocase; classtype:trojan-activity; sid:100000560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.210.89.79",nocase; classtype:trojan-activity; sid:100000561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.43.33.202",nocase; classtype:trojan-activity; sid:100000562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.5.15.95",nocase; classtype:trojan-activity; sid:100000563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.66.60",nocase; classtype:trojan-activity; sid:100000564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.93.115",nocase; classtype:trojan-activity; sid:100000565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.141.142",nocase; classtype:trojan-activity; sid:100000566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.8.11",nocase; classtype:trojan-activity; sid:100000567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.7.75.99",nocase; classtype:trojan-activity; sid:100000568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.173.168",nocase; classtype:trojan-activity; sid:100000569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.174.3",nocase; classtype:trojan-activity; sid:100000570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.210.232",nocase; classtype:trojan-activity; sid:100000571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.114.164",nocase; classtype:trojan-activity; sid:100000572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.96.8",nocase; classtype:trojan-activity; sid:100000573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.121.44.222",nocase; classtype:trojan-activity; sid:100000574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.122.71.122",nocase; classtype:trojan-activity; sid:100000575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.123.53.25",nocase; classtype:trojan-activity; sid:100000576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.127.155.220",nocase; classtype:trojan-activity; sid:100000577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.141.11.56",nocase; classtype:trojan-activity; sid:100000578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.15.142.137",nocase; classtype:trojan-activity; sid:100000579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.159.22.144",nocase; classtype:trojan-activity; sid:100000580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.170.234.142",nocase; classtype:trojan-activity; sid:100000581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.185.31.2",nocase; classtype:trojan-activity; sid:100000582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.190.36.8",nocase; classtype:trojan-activity; sid:100000583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.20.104.26",nocase; classtype:trojan-activity; sid:100000584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.225.11.163",nocase; classtype:trojan-activity; sid:100000585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.23.57.130",nocase; classtype:trojan-activity; sid:100000586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.230.171.198",nocase; classtype:trojan-activity; sid:100000587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.231.103.95",nocase; classtype:trojan-activity; sid:100000588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.237.226.202",nocase; classtype:trojan-activity; sid:100000589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.239.15.74",nocase; classtype:trojan-activity; sid:100000590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.24.116.173",nocase; classtype:trojan-activity; sid:100000591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.25.101.86",nocase; classtype:trojan-activity; sid:100000592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.254.43.215",nocase; classtype:trojan-activity; sid:100000593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.254.76.17",nocase; classtype:trojan-activity; sid:100000594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.101.125",nocase; classtype:trojan-activity; sid:100000595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.98.151",nocase; classtype:trojan-activity; sid:100000596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.88.99.236",nocase; classtype:trojan-activity; sid:100000597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.100.150.204",nocase; classtype:trojan-activity; sid:100000598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.159.178.39",nocase; classtype:trojan-activity; sid:100000599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.160.147.53",nocase; classtype:trojan-activity; sid:100000600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.176.44.34",nocase; classtype:trojan-activity; sid:100000601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.188.86.225",nocase; classtype:trojan-activity; sid:100000602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.66.28",nocase; classtype:trojan-activity; sid:100000603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.72.23",nocase; classtype:trojan-activity; sid:100000604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.79.27",nocase; classtype:trojan-activity; sid:100000605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.83.86",nocase; classtype:trojan-activity; sid:100000606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.37.85",nocase; classtype:trojan-activity; sid:100000607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.41.23",nocase; classtype:trojan-activity; sid:100000608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.29.37",nocase; classtype:trojan-activity; sid:100000609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.33.214",nocase; classtype:trojan-activity; sid:100000610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.0.240.58",nocase; classtype:trojan-activity; sid:100000611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.54.57",nocase; classtype:trojan-activity; sid:100000612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.238",nocase; classtype:trojan-activity; sid:100000613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.244",nocase; classtype:trojan-activity; sid:100000614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.170.237",nocase; classtype:trojan-activity; sid:100000615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.182.187",nocase; classtype:trojan-activity; sid:100000616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.19.248",nocase; classtype:trojan-activity; sid:100000617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.200.98",nocase; classtype:trojan-activity; sid:100000618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.238.188",nocase; classtype:trojan-activity; sid:100000619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.128.133.91",nocase; classtype:trojan-activity; sid:100000620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.129.84.36",nocase; classtype:trojan-activity; sid:100000621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.208.52",nocase; classtype:trojan-activity; sid:100000622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.23.110",nocase; classtype:trojan-activity; sid:100000623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.27.19",nocase; classtype:trojan-activity; sid:100000624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.37.182",nocase; classtype:trojan-activity; sid:100000625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.61.210",nocase; classtype:trojan-activity; sid:100000626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.77.225",nocase; classtype:trojan-activity; sid:100000627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.131.186.250",nocase; classtype:trojan-activity; sid:100000628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.132.219.147",nocase; classtype:trojan-activity; sid:100000629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.125.77",nocase; classtype:trojan-activity; sid:100000630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.98.135",nocase; classtype:trojan-activity; sid:100000631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.134.14.130",nocase; classtype:trojan-activity; sid:100000632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.134.50.186",nocase; classtype:trojan-activity; sid:100000633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.120.130",nocase; classtype:trojan-activity; sid:100000634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.199.130",nocase; classtype:trojan-activity; sid:100000635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.153.80.178",nocase; classtype:trojan-activity; sid:100000636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.116.116",nocase; classtype:trojan-activity; sid:100000637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.236.114",nocase; classtype:trojan-activity; sid:100000638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.94.1",nocase; classtype:trojan-activity; sid:100000639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.156.136.21",nocase; classtype:trojan-activity; sid:100000640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.8.100",nocase; classtype:trojan-activity; sid:100000641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.183.121.60",nocase; classtype:trojan-activity; sid:100000642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.191.150.147",nocase; classtype:trojan-activity; sid:100000643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.191.164.92",nocase; classtype:trojan-activity; sid:100000644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.101.163",nocase; classtype:trojan-activity; sid:100000645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.194.233",nocase; classtype:trojan-activity; sid:100000646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.149.235",nocase; classtype:trojan-activity; sid:100000647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.53.237",nocase; classtype:trojan-activity; sid:100000648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.235.37",nocase; classtype:trojan-activity; sid:100000649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.35.146",nocase; classtype:trojan-activity; sid:100000650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.52.79",nocase; classtype:trojan-activity; sid:100000651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.60.238",nocase; classtype:trojan-activity; sid:100000652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.112.240",nocase; classtype:trojan-activity; sid:100000653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.184.191",nocase; classtype:trojan-activity; sid:100000654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.98.141",nocase; classtype:trojan-activity; sid:100000655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.212.29.154",nocase; classtype:trojan-activity; sid:100000656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.213.225.130",nocase; classtype:trojan-activity; sid:100000657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.130.162",nocase; classtype:trojan-activity; sid:100000658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.152.249",nocase; classtype:trojan-activity; sid:100000659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.116.110",nocase; classtype:trojan-activity; sid:100000660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.184.57",nocase; classtype:trojan-activity; sid:100000661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.235.226.3",nocase; classtype:trojan-activity; sid:100000662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.103.89",nocase; classtype:trojan-activity; sid:100000663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.181.57",nocase; classtype:trojan-activity; sid:100000664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.79.61",nocase; classtype:trojan-activity; sid:100000665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.148.58",nocase; classtype:trojan-activity; sid:100000666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.184.124",nocase; classtype:trojan-activity; sid:100000667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.28.217.23",nocase; classtype:trojan-activity; sid:100000668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.189.116",nocase; classtype:trojan-activity; sid:100000669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.5.242",nocase; classtype:trojan-activity; sid:100000670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.184.82",nocase; classtype:trojan-activity; sid:100000671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.119.108.87",nocase; classtype:trojan-activity; sid:100000672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.221.150",nocase; classtype:trojan-activity; sid:100000673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.76.230",nocase; classtype:trojan-activity; sid:100000674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.130.110.167",nocase; classtype:trojan-activity; sid:100000675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.130.40.31",nocase; classtype:trojan-activity; sid:100000676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.104.82",nocase; classtype:trojan-activity; sid:100000677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.151.135",nocase; classtype:trojan-activity; sid:100000678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.203.190",nocase; classtype:trojan-activity; sid:100000679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.24.185",nocase; classtype:trojan-activity; sid:100000680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.26.243",nocase; classtype:trojan-activity; sid:100000681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.54.33",nocase; classtype:trojan-activity; sid:100000682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.132.110.150",nocase; classtype:trojan-activity; sid:100000683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.135.34.49",nocase; classtype:trojan-activity; sid:100000684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.136.175",nocase; classtype:trojan-activity; sid:100000685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.236.6",nocase; classtype:trojan-activity; sid:100000686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.160.126.238",nocase; classtype:trojan-activity; sid:100000687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.163.193",nocase; classtype:trojan-activity; sid:100000688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.65.64",nocase; classtype:trojan-activity; sid:100000689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.72.102",nocase; classtype:trojan-activity; sid:100000690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.165.123.7",nocase; classtype:trojan-activity; sid:100000691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.187.111.160",nocase; classtype:trojan-activity; sid:100000692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.199.56.198",nocase; classtype:trojan-activity; sid:100000693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.230.174.233",nocase; classtype:trojan-activity; sid:100000694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.254.251.54",nocase; classtype:trojan-activity; sid:100000695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.5.92.20",nocase; classtype:trojan-activity; sid:100000696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.6.0.4",nocase; classtype:trojan-activity; sid:100000697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.67.89.28",nocase; classtype:trojan-activity; sid:100000698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.7.254.85",nocase; classtype:trojan-activity; sid:100000699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.80.46.73",nocase; classtype:trojan-activity; sid:100000700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.91.135.234",nocase; classtype:trojan-activity; sid:100000701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.91.237.147",nocase; classtype:trojan-activity; sid:100000702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.93.94.207",nocase; classtype:trojan-activity; sid:100000703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.128.28.161",nocase; classtype:trojan-activity; sid:100000704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.142.93.34",nocase; classtype:trojan-activity; sid:100000705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.191.113.212",nocase; classtype:trojan-activity; sid:100000706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.1.235",nocase; classtype:trojan-activity; sid:100000707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.73.6",nocase; classtype:trojan-activity; sid:100000708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.75.22",nocase; classtype:trojan-activity; sid:100000709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.215.9",nocase; classtype:trojan-activity; sid:100000710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.53.9",nocase; classtype:trojan-activity; sid:100000711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.63.67",nocase; classtype:trojan-activity; sid:100000712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.129.159",nocase; classtype:trojan-activity; sid:100000713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.79.200.104",nocase; classtype:trojan-activity; sid:100000714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"128.116.133.92",nocase; classtype:trojan-activity; sid:100000715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"130.255.159.133",nocase; classtype:trojan-activity; sid:100000716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"134.195.139.4",nocase; classtype:trojan-activity; sid:100000717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"135.148.36.127",nocase; classtype:trojan-activity; sid:100000718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"138.99.204.224",nocase; classtype:trojan-activity; sid:100000719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.159.226.180",nocase; classtype:trojan-activity; sid:100000720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.170.173.198",nocase; classtype:trojan-activity; sid:100000721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.216.102.151",nocase; classtype:trojan-activity; sid:100000722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.227.46.137",nocase; classtype:trojan-activity; sid:100000723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.102.17.222",nocase; classtype:trojan-activity; sid:100000724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.136.80.242",nocase; classtype:trojan-activity; sid:100000725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.51",nocase; classtype:trojan-activity; sid:100000726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.178.163.235",nocase; classtype:trojan-activity; sid:100000727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.189.247.118",nocase; classtype:trojan-activity; sid:100000728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.37.222.190",nocase; classtype:trojan-activity; sid:100000729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.45.127.110",nocase; classtype:trojan-activity; sid:100000730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.25.17",nocase; classtype:trojan-activity; sid:100000731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.98.241",nocase; classtype:trojan-activity; sid:100000732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.55.29.2",nocase; classtype:trojan-activity; sid:100000733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"141.105.65.94",nocase; classtype:trojan-activity; sid:100000734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.11.216.5",nocase; classtype:trojan-activity; sid:100000735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.177.56.127",nocase; classtype:trojan-activity; sid:100000736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"146.71.79.230",nocase; classtype:trojan-activity; sid:100000737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"148.69.108.177",nocase; classtype:trojan-activity; sid:100000738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.20.176.179",nocase; classtype:trojan-activity; sid:100000739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.134",nocase; classtype:trojan-activity; sid:100000740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.172",nocase; classtype:trojan-activity; sid:100000741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.184",nocase; classtype:trojan-activity; sid:100000742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.38",nocase; classtype:trojan-activity; sid:100000743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.99",nocase; classtype:trojan-activity; sid:100000744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.3.124.223",nocase; classtype:trojan-activity; sid:100000745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.3.85.55",nocase; classtype:trojan-activity; sid:100000746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14karatvisions.com",nocase; classtype:trojan-activity; sid:100000747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"150.116.207.99",nocase; classtype:trojan-activity; sid:100000748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.177.163.87",nocase; classtype:trojan-activity; sid:100000749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.33.230.191",nocase; classtype:trojan-activity; sid:100000750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.234.167",nocase; classtype:trojan-activity; sid:100000751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.47.145",nocase; classtype:trojan-activity; sid:100000752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.152.106",nocase; classtype:trojan-activity; sid:100000753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.135.92",nocase; classtype:trojan-activity; sid:100000754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.36.126.35",nocase; classtype:trojan-activity; sid:100000755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"155.138.134.44",nocase; classtype:trojan-activity; sid:100000756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.101.165.14",nocase; classtype:trojan-activity; sid:100000757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.174.213.128",nocase; classtype:trojan-activity; sid:100000758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.247.195.165",nocase; classtype:trojan-activity; sid:100000759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.51.125.115",nocase; classtype:trojan-activity; sid:100000760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"159.224.74.112",nocase; classtype:trojan-activity; sid:100000761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.194.28.60",nocase; classtype:trojan-activity; sid:100000762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.209.98.174",nocase; classtype:trojan-activity; sid:100000763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.53.206.228",nocase; classtype:trojan-activity; sid:100000764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"165.90.16.5",nocase; classtype:trojan-activity; sid:100000765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"168.205.223.254",nocase; classtype:trojan-activity; sid:100000766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"170.81.238.178",nocase; classtype:trojan-activity; sid:100000767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.113.36.216",nocase; classtype:trojan-activity; sid:100000768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.113.38.107",nocase; classtype:trojan-activity; sid:100000769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.121.255.10",nocase; classtype:trojan-activity; sid:100000770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.112.42",nocase; classtype:trojan-activity; sid:100000771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.114.181",nocase; classtype:trojan-activity; sid:100000772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.176.217",nocase; classtype:trojan-activity; sid:100000773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.179.178",nocase; classtype:trojan-activity; sid:100000774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.162.156",nocase; classtype:trojan-activity; sid:100000775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.174.198",nocase; classtype:trojan-activity; sid:100000776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.105.36.168",nocase; classtype:trojan-activity; sid:100000777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.114.244.127",nocase; classtype:trojan-activity; sid:100000778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.185",nocase; classtype:trojan-activity; sid:100000779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.190",nocase; classtype:trojan-activity; sid:100000780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.81.19",nocase; classtype:trojan-activity; sid:100000781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.93.194.114",nocase; classtype:trojan-activity; sid:100000782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.167.85.89",nocase; classtype:trojan-activity; sid:100000783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.169.46.85",nocase; classtype:trojan-activity; sid:100000784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.19.58.108",nocase; classtype:trojan-activity; sid:100000785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.233.85.171",nocase; classtype:trojan-activity; sid:100000786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.235.209.70",nocase; classtype:trojan-activity; sid:100000787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.25.113.8",nocase; classtype:trojan-activity; sid:100000788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.95.134",nocase; classtype:trojan-activity; sid:100000789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.97.25",nocase; classtype:trojan-activity; sid:100000790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.119.108",nocase; classtype:trojan-activity; sid:100000791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.92.166",nocase; classtype:trojan-activity; sid:100000792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.106.33.85",nocase; classtype:trojan-activity; sid:100000793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.48.181.23",nocase; classtype:trojan-activity; sid:100000794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.61.3.149",nocase; classtype:trojan-activity; sid:100000795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.73.246.193",nocase; classtype:trojan-activity; sid:100000796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.81.78.7",nocase; classtype:trojan-activity; sid:100000797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.83.73.163",nocase; classtype:trojan-activity; sid:100000798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.10.147.167",nocase; classtype:trojan-activity; sid:100000799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.11.193.66",nocase; classtype:trojan-activity; sid:100000800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.11.65.112",nocase; classtype:trojan-activity; sid:100000801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.117.66.74",nocase; classtype:trojan-activity; sid:100000802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.145.200.216",nocase; classtype:trojan-activity; sid:100000803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.169.13.182",nocase; classtype:trojan-activity; sid:100000804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.201.104.192",nocase; classtype:trojan-activity; sid:100000805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.208.230.8",nocase; classtype:trojan-activity; sid:100000806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.212.6.169",nocase; classtype:trojan-activity; sid:100000807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.42.46.118",nocase; classtype:trojan-activity; sid:100000808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.9.24.110",nocase; classtype:trojan-activity; sid:100000809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.9.90.89",nocase; classtype:trojan-activity; sid:100000810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.14",nocase; classtype:trojan-activity; sid:100000811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.249",nocase; classtype:trojan-activity; sid:100000812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.35",nocase; classtype:trojan-activity; sid:100000813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.63",nocase; classtype:trojan-activity; sid:100000814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.66",nocase; classtype:trojan-activity; sid:100000815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.67",nocase; classtype:trojan-activity; sid:100000816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.104",nocase; classtype:trojan-activity; sid:100000817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.113",nocase; classtype:trojan-activity; sid:100000818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.138",nocase; classtype:trojan-activity; sid:100000819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.60",nocase; classtype:trojan-activity; sid:100000820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.65",nocase; classtype:trojan-activity; sid:100000821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.66",nocase; classtype:trojan-activity; sid:100000822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.68",nocase; classtype:trojan-activity; sid:100000823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.84",nocase; classtype:trojan-activity; sid:100000824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.91",nocase; classtype:trojan-activity; sid:100000825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.93",nocase; classtype:trojan-activity; sid:100000826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.12.117.70",nocase; classtype:trojan-activity; sid:100000827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.4.115",nocase; classtype:trojan-activity; sid:100000828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.115",nocase; classtype:trojan-activity; sid:100000829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.127",nocase; classtype:trojan-activity; sid:100000830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.9.243",nocase; classtype:trojan-activity; sid:100000831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.124.7.225",nocase; classtype:trojan-activity; sid:100000832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.221.242.166",nocase; classtype:trojan-activity; sid:100000833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.240.84.106",nocase; classtype:trojan-activity; sid:100000834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.11.92.78",nocase; classtype:trojan-activity; sid:100000835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.131.226.235",nocase; classtype:trojan-activity; sid:100000836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.229.64.218",nocase; classtype:trojan-activity; sid:100000837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.54.82.154",nocase; classtype:trojan-activity; sid:100000838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.86.99.5",nocase; classtype:trojan-activity; sid:100000839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.124.182.187",nocase; classtype:trojan-activity; sid:100000840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.142.15",nocase; classtype:trojan-activity; sid:100000841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.150.174.65",nocase; classtype:trojan-activity; sid:100000842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.165.122.141",nocase; classtype:trojan-activity; sid:100000843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.0.200",nocase; classtype:trojan-activity; sid:100000844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.137",nocase; classtype:trojan-activity; sid:100000845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.153",nocase; classtype:trojan-activity; sid:100000846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.179",nocase; classtype:trojan-activity; sid:100000847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.248",nocase; classtype:trojan-activity; sid:100000848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.249",nocase; classtype:trojan-activity; sid:100000849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.250",nocase; classtype:trojan-activity; sid:100000850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.44",nocase; classtype:trojan-activity; sid:100000851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.80",nocase; classtype:trojan-activity; sid:100000852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.110",nocase; classtype:trojan-activity; sid:100000853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.232",nocase; classtype:trojan-activity; sid:100000854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.133",nocase; classtype:trojan-activity; sid:100000855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.171",nocase; classtype:trojan-activity; sid:100000856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.67",nocase; classtype:trojan-activity; sid:100000857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.98",nocase; classtype:trojan-activity; sid:100000858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.145",nocase; classtype:trojan-activity; sid:100000859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.155",nocase; classtype:trojan-activity; sid:100000860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.69",nocase; classtype:trojan-activity; sid:100000861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.125",nocase; classtype:trojan-activity; sid:100000862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.95",nocase; classtype:trojan-activity; sid:100000863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.118",nocase; classtype:trojan-activity; sid:100000864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.193",nocase; classtype:trojan-activity; sid:100000865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.201",nocase; classtype:trojan-activity; sid:100000866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.0",nocase; classtype:trojan-activity; sid:100000867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.245",nocase; classtype:trojan-activity; sid:100000868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.83",nocase; classtype:trojan-activity; sid:100000869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.105",nocase; classtype:trojan-activity; sid:100000870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.149",nocase; classtype:trojan-activity; sid:100000871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.87",nocase; classtype:trojan-activity; sid:100000872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.129",nocase; classtype:trojan-activity; sid:100000873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.26",nocase; classtype:trojan-activity; sid:100000874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.126",nocase; classtype:trojan-activity; sid:100000875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.239",nocase; classtype:trojan-activity; sid:100000876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.252",nocase; classtype:trojan-activity; sid:100000877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.190",nocase; classtype:trojan-activity; sid:100000878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.195",nocase; classtype:trojan-activity; sid:100000879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.206",nocase; classtype:trojan-activity; sid:100000880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.135",nocase; classtype:trojan-activity; sid:100000881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.139",nocase; classtype:trojan-activity; sid:100000882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.147",nocase; classtype:trojan-activity; sid:100000883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.159",nocase; classtype:trojan-activity; sid:100000884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.46",nocase; classtype:trojan-activity; sid:100000885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.58",nocase; classtype:trojan-activity; sid:100000886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.27",nocase; classtype:trojan-activity; sid:100000887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.114",nocase; classtype:trojan-activity; sid:100000888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.63",nocase; classtype:trojan-activity; sid:100000889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.110",nocase; classtype:trojan-activity; sid:100000890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.209",nocase; classtype:trojan-activity; sid:100000891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.101",nocase; classtype:trojan-activity; sid:100000892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.138",nocase; classtype:trojan-activity; sid:100000893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.168",nocase; classtype:trojan-activity; sid:100000894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.90",nocase; classtype:trojan-activity; sid:100000895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.30",nocase; classtype:trojan-activity; sid:100000896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.112",nocase; classtype:trojan-activity; sid:100000897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.146",nocase; classtype:trojan-activity; sid:100000898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.210",nocase; classtype:trojan-activity; sid:100000899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.102",nocase; classtype:trojan-activity; sid:100000900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.114",nocase; classtype:trojan-activity; sid:100000901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.69",nocase; classtype:trojan-activity; sid:100000902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.70",nocase; classtype:trojan-activity; sid:100000903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.93",nocase; classtype:trojan-activity; sid:100000904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.123",nocase; classtype:trojan-activity; sid:100000905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.151",nocase; classtype:trojan-activity; sid:100000906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.199",nocase; classtype:trojan-activity; sid:100000907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.228",nocase; classtype:trojan-activity; sid:100000908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.28",nocase; classtype:trojan-activity; sid:100000909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.74",nocase; classtype:trojan-activity; sid:100000910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.9",nocase; classtype:trojan-activity; sid:100000911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.1",nocase; classtype:trojan-activity; sid:100000912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.168",nocase; classtype:trojan-activity; sid:100000913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.191",nocase; classtype:trojan-activity; sid:100000914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.2",nocase; classtype:trojan-activity; sid:100000915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.202",nocase; classtype:trojan-activity; sid:100000916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.248",nocase; classtype:trojan-activity; sid:100000917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.26",nocase; classtype:trojan-activity; sid:100000918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.30",nocase; classtype:trojan-activity; sid:100000919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.48",nocase; classtype:trojan-activity; sid:100000920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.91",nocase; classtype:trojan-activity; sid:100000921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.131",nocase; classtype:trojan-activity; sid:100000922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.155",nocase; classtype:trojan-activity; sid:100000923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.4",nocase; classtype:trojan-activity; sid:100000924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.79",nocase; classtype:trojan-activity; sid:100000925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.14",nocase; classtype:trojan-activity; sid:100000926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.160",nocase; classtype:trojan-activity; sid:100000927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.220",nocase; classtype:trojan-activity; sid:100000928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.88",nocase; classtype:trojan-activity; sid:100000929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.129",nocase; classtype:trojan-activity; sid:100000930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.153",nocase; classtype:trojan-activity; sid:100000931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.252",nocase; classtype:trojan-activity; sid:100000932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.46",nocase; classtype:trojan-activity; sid:100000933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.202",nocase; classtype:trojan-activity; sid:100000934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.231",nocase; classtype:trojan-activity; sid:100000935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.43",nocase; classtype:trojan-activity; sid:100000936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.222",nocase; classtype:trojan-activity; sid:100000937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.254",nocase; classtype:trojan-activity; sid:100000938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.199",nocase; classtype:trojan-activity; sid:100000939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.215",nocase; classtype:trojan-activity; sid:100000940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.35",nocase; classtype:trojan-activity; sid:100000941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.108",nocase; classtype:trojan-activity; sid:100000942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.116",nocase; classtype:trojan-activity; sid:100000943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.251",nocase; classtype:trojan-activity; sid:100000944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.7",nocase; classtype:trojan-activity; sid:100000945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.73",nocase; classtype:trojan-activity; sid:100000946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.118",nocase; classtype:trojan-activity; sid:100000947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.61",nocase; classtype:trojan-activity; sid:100000948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.23",nocase; classtype:trojan-activity; sid:100000949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.75",nocase; classtype:trojan-activity; sid:100000950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.163",nocase; classtype:trojan-activity; sid:100000951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.174",nocase; classtype:trojan-activity; sid:100000952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.91",nocase; classtype:trojan-activity; sid:100000953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.118",nocase; classtype:trojan-activity; sid:100000954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.123",nocase; classtype:trojan-activity; sid:100000955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.209",nocase; classtype:trojan-activity; sid:100000956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.5",nocase; classtype:trojan-activity; sid:100000957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.117",nocase; classtype:trojan-activity; sid:100000958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.70",nocase; classtype:trojan-activity; sid:100000959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.97",nocase; classtype:trojan-activity; sid:100000960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.149",nocase; classtype:trojan-activity; sid:100000961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.184",nocase; classtype:trojan-activity; sid:100000962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.238",nocase; classtype:trojan-activity; sid:100000963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.237",nocase; classtype:trojan-activity; sid:100000964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.144",nocase; classtype:trojan-activity; sid:100000965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.176",nocase; classtype:trojan-activity; sid:100000966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.146",nocase; classtype:trojan-activity; sid:100000967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.172",nocase; classtype:trojan-activity; sid:100000968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.117",nocase; classtype:trojan-activity; sid:100000969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.152",nocase; classtype:trojan-activity; sid:100000970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.177",nocase; classtype:trojan-activity; sid:100000971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.56",nocase; classtype:trojan-activity; sid:100000972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.215",nocase; classtype:trojan-activity; sid:100000973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.114",nocase; classtype:trojan-activity; sid:100000974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.127",nocase; classtype:trojan-activity; sid:100000975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.171",nocase; classtype:trojan-activity; sid:100000976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.213",nocase; classtype:trojan-activity; sid:100000977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.32",nocase; classtype:trojan-activity; sid:100000978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.37",nocase; classtype:trojan-activity; sid:100000979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.46",nocase; classtype:trojan-activity; sid:100000980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.239",nocase; classtype:trojan-activity; sid:100000981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.47",nocase; classtype:trojan-activity; sid:100000982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.2",nocase; classtype:trojan-activity; sid:100000983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.21",nocase; classtype:trojan-activity; sid:100000984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.172",nocase; classtype:trojan-activity; sid:100000985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.214",nocase; classtype:trojan-activity; sid:100000986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.133",nocase; classtype:trojan-activity; sid:100000987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.151",nocase; classtype:trojan-activity; sid:100000988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.213",nocase; classtype:trojan-activity; sid:100000989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.251",nocase; classtype:trojan-activity; sid:100000990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.73",nocase; classtype:trojan-activity; sid:100000991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.146",nocase; classtype:trojan-activity; sid:100000992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.220",nocase; classtype:trojan-activity; sid:100000993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.89",nocase; classtype:trojan-activity; sid:100000994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.7",nocase; classtype:trojan-activity; sid:100000995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.217",nocase; classtype:trojan-activity; sid:100000996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.247",nocase; classtype:trojan-activity; sid:100000997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.253",nocase; classtype:trojan-activity; sid:100000998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.36",nocase; classtype:trojan-activity; sid:100000999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.83",nocase; classtype:trojan-activity; sid:100001000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.126",nocase; classtype:trojan-activity; sid:100001001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.218",nocase; classtype:trojan-activity; sid:100001002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.57",nocase; classtype:trojan-activity; sid:100001003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.6",nocase; classtype:trojan-activity; sid:100001004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.103",nocase; classtype:trojan-activity; sid:100001005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.132",nocase; classtype:trojan-activity; sid:100001006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.200",nocase; classtype:trojan-activity; sid:100001007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.144",nocase; classtype:trojan-activity; sid:100001008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.72",nocase; classtype:trojan-activity; sid:100001009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.136",nocase; classtype:trojan-activity; sid:100001010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.166",nocase; classtype:trojan-activity; sid:100001011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.228",nocase; classtype:trojan-activity; sid:100001012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.101",nocase; classtype:trojan-activity; sid:100001013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.6",nocase; classtype:trojan-activity; sid:100001014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.121",nocase; classtype:trojan-activity; sid:100001015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.238",nocase; classtype:trojan-activity; sid:100001016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.244",nocase; classtype:trojan-activity; sid:100001017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.0",nocase; classtype:trojan-activity; sid:100001018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.217",nocase; classtype:trojan-activity; sid:100001019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.70",nocase; classtype:trojan-activity; sid:100001020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.90",nocase; classtype:trojan-activity; sid:100001021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.201",nocase; classtype:trojan-activity; sid:100001022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.205",nocase; classtype:trojan-activity; sid:100001023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.214",nocase; classtype:trojan-activity; sid:100001024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.26",nocase; classtype:trojan-activity; sid:100001025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.129",nocase; classtype:trojan-activity; sid:100001026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.137",nocase; classtype:trojan-activity; sid:100001027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.243",nocase; classtype:trojan-activity; sid:100001028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.41",nocase; classtype:trojan-activity; sid:100001029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.42",nocase; classtype:trojan-activity; sid:100001030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.8",nocase; classtype:trojan-activity; sid:100001031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.143",nocase; classtype:trojan-activity; sid:100001032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.51",nocase; classtype:trojan-activity; sid:100001033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.12",nocase; classtype:trojan-activity; sid:100001034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.57",nocase; classtype:trojan-activity; sid:100001035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.10",nocase; classtype:trojan-activity; sid:100001036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.177",nocase; classtype:trojan-activity; sid:100001037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.236",nocase; classtype:trojan-activity; sid:100001038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.56",nocase; classtype:trojan-activity; sid:100001039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.180",nocase; classtype:trojan-activity; sid:100001040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.212",nocase; classtype:trojan-activity; sid:100001041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.216",nocase; classtype:trojan-activity; sid:100001042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.151",nocase; classtype:trojan-activity; sid:100001043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.254",nocase; classtype:trojan-activity; sid:100001044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.5",nocase; classtype:trojan-activity; sid:100001045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.58",nocase; classtype:trojan-activity; sid:100001046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.14",nocase; classtype:trojan-activity; sid:100001047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.211",nocase; classtype:trojan-activity; sid:100001048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.11",nocase; classtype:trojan-activity; sid:100001049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.82",nocase; classtype:trojan-activity; sid:100001050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.87",nocase; classtype:trojan-activity; sid:100001051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.134",nocase; classtype:trojan-activity; sid:100001052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.179",nocase; classtype:trojan-activity; sid:100001053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.183",nocase; classtype:trojan-activity; sid:100001054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.79",nocase; classtype:trojan-activity; sid:100001055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.131",nocase; classtype:trojan-activity; sid:100001056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.33",nocase; classtype:trojan-activity; sid:100001057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.115",nocase; classtype:trojan-activity; sid:100001058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.140",nocase; classtype:trojan-activity; sid:100001059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.141",nocase; classtype:trojan-activity; sid:100001060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.157",nocase; classtype:trojan-activity; sid:100001061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.182",nocase; classtype:trojan-activity; sid:100001062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.195",nocase; classtype:trojan-activity; sid:100001063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.134",nocase; classtype:trojan-activity; sid:100001064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.209",nocase; classtype:trojan-activity; sid:100001065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.212",nocase; classtype:trojan-activity; sid:100001066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.221",nocase; classtype:trojan-activity; sid:100001067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.235",nocase; classtype:trojan-activity; sid:100001068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.232",nocase; classtype:trojan-activity; sid:100001069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.70",nocase; classtype:trojan-activity; sid:100001070; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.81",nocase; classtype:trojan-activity; sid:100001071; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.21",nocase; classtype:trojan-activity; sid:100001072; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.156",nocase; classtype:trojan-activity; sid:100001073; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.186",nocase; classtype:trojan-activity; sid:100001074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.192",nocase; classtype:trojan-activity; sid:100001075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.211",nocase; classtype:trojan-activity; sid:100001076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.116",nocase; classtype:trojan-activity; sid:100001077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.123",nocase; classtype:trojan-activity; sid:100001078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.209",nocase; classtype:trojan-activity; sid:100001079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.44",nocase; classtype:trojan-activity; sid:100001080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.128",nocase; classtype:trojan-activity; sid:100001081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.153",nocase; classtype:trojan-activity; sid:100001082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.67",nocase; classtype:trojan-activity; sid:100001083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.105",nocase; classtype:trojan-activity; sid:100001084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.107",nocase; classtype:trojan-activity; sid:100001085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.14",nocase; classtype:trojan-activity; sid:100001086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.21",nocase; classtype:trojan-activity; sid:100001087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.35",nocase; classtype:trojan-activity; sid:100001088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.60",nocase; classtype:trojan-activity; sid:100001089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.79",nocase; classtype:trojan-activity; sid:100001090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.212",nocase; classtype:trojan-activity; sid:100001091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.218",nocase; classtype:trojan-activity; sid:100001092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.222",nocase; classtype:trojan-activity; sid:100001093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.65",nocase; classtype:trojan-activity; sid:100001094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.73.42",nocase; classtype:trojan-activity; sid:100001095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.181",nocase; classtype:trojan-activity; sid:100001096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.244",nocase; classtype:trojan-activity; sid:100001097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.248",nocase; classtype:trojan-activity; sid:100001098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.46",nocase; classtype:trojan-activity; sid:100001099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.47",nocase; classtype:trojan-activity; sid:100001100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.169",nocase; classtype:trojan-activity; sid:100001101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.2",nocase; classtype:trojan-activity; sid:100001102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.181",nocase; classtype:trojan-activity; sid:100001103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.89",nocase; classtype:trojan-activity; sid:100001104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.176",nocase; classtype:trojan-activity; sid:100001105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.226",nocase; classtype:trojan-activity; sid:100001106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.235",nocase; classtype:trojan-activity; sid:100001107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.31",nocase; classtype:trojan-activity; sid:100001108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.2",nocase; classtype:trojan-activity; sid:100001109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.215",nocase; classtype:trojan-activity; sid:100001110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.61",nocase; classtype:trojan-activity; sid:100001111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.23",nocase; classtype:trojan-activity; sid:100001112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.53",nocase; classtype:trojan-activity; sid:100001113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.59",nocase; classtype:trojan-activity; sid:100001114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.146",nocase; classtype:trojan-activity; sid:100001115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.42",nocase; classtype:trojan-activity; sid:100001116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.91",nocase; classtype:trojan-activity; sid:100001117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.166",nocase; classtype:trojan-activity; sid:100001118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.4",nocase; classtype:trojan-activity; sid:100001119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.217",nocase; classtype:trojan-activity; sid:100001120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.6",nocase; classtype:trojan-activity; sid:100001121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.179",nocase; classtype:trojan-activity; sid:100001122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.198",nocase; classtype:trojan-activity; sid:100001123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.4",nocase; classtype:trojan-activity; sid:100001124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.81",nocase; classtype:trojan-activity; sid:100001125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.1",nocase; classtype:trojan-activity; sid:100001126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.102",nocase; classtype:trojan-activity; sid:100001127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.92",nocase; classtype:trojan-activity; sid:100001128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.143",nocase; classtype:trojan-activity; sid:100001129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.182",nocase; classtype:trojan-activity; sid:100001130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.27",nocase; classtype:trojan-activity; sid:100001131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.32",nocase; classtype:trojan-activity; sid:100001132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.40",nocase; classtype:trojan-activity; sid:100001133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.61",nocase; classtype:trojan-activity; sid:100001134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.120",nocase; classtype:trojan-activity; sid:100001135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.218",nocase; classtype:trojan-activity; sid:100001136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.251",nocase; classtype:trojan-activity; sid:100001137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.14",nocase; classtype:trojan-activity; sid:100001138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.83",nocase; classtype:trojan-activity; sid:100001139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.120",nocase; classtype:trojan-activity; sid:100001140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.130",nocase; classtype:trojan-activity; sid:100001141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.77",nocase; classtype:trojan-activity; sid:100001142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.19.183.14",nocase; classtype:trojan-activity; sid:100001143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.205.101.33",nocase; classtype:trojan-activity; sid:100001144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.21.164.68",nocase; classtype:trojan-activity; sid:100001145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.217.8.194",nocase; classtype:trojan-activity; sid:100001146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.22.117.102",nocase; classtype:trojan-activity; sid:100001147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.222.252.130",nocase; classtype:trojan-activity; sid:100001148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.34.183.30",nocase; classtype:trojan-activity; sid:100001149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.48.235.59",nocase; classtype:trojan-activity; sid:100001150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.72.91.172",nocase; classtype:trojan-activity; sid:100001151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.95.136.35",nocase; classtype:trojan-activity; sid:100001152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.159.58.134",nocase; classtype:trojan-activity; sid:100001153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.60.84.7",nocase; classtype:trojan-activity; sid:100001154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.99.210.161",nocase; classtype:trojan-activity; sid:100001155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.114.60.229",nocase; classtype:trojan-activity; sid:100001156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.116.203.220",nocase; classtype:trojan-activity; sid:100001157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.122.13.227",nocase; classtype:trojan-activity; sid:100001158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.123.208.250",nocase; classtype:trojan-activity; sid:100001159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.125.44.194",nocase; classtype:trojan-activity; sid:100001160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.157.66.204",nocase; classtype:trojan-activity; sid:100001161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.175.236.209",nocase; classtype:trojan-activity; sid:100001162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.105.41",nocase; classtype:trojan-activity; sid:100001163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.110.243",nocase; classtype:trojan-activity; sid:100001164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.165.230",nocase; classtype:trojan-activity; sid:100001165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.214.171",nocase; classtype:trojan-activity; sid:100001166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.34.51",nocase; classtype:trojan-activity; sid:100001167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.96.248",nocase; classtype:trojan-activity; sid:100001168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.104.65",nocase; classtype:trojan-activity; sid:100001169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.180.6",nocase; classtype:trojan-activity; sid:100001170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.242.73",nocase; classtype:trojan-activity; sid:100001171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.218.5.171",nocase; classtype:trojan-activity; sid:100001172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.248.80.38",nocase; classtype:trojan-activity; sid:100001173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.111.36",nocase; classtype:trojan-activity; sid:100001174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.53.93",nocase; classtype:trojan-activity; sid:100001175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.94.170.166",nocase; classtype:trojan-activity; sid:100001176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.138.154",nocase; classtype:trojan-activity; sid:100001177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.218.238",nocase; classtype:trojan-activity; sid:100001178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.218.6",nocase; classtype:trojan-activity; sid:100001179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.143.60.163",nocase; classtype:trojan-activity; sid:100001180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.193.107.10",nocase; classtype:trojan-activity; sid:100001181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.222",nocase; classtype:trojan-activity; sid:100001182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.230",nocase; classtype:trojan-activity; sid:100001183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.210.45.42",nocase; classtype:trojan-activity; sid:100001184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.215.47.82",nocase; classtype:trojan-activity; sid:100001185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.224.242.131",nocase; classtype:trojan-activity; sid:100001186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.236.4",nocase; classtype:trojan-activity; sid:100001187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.59.162",nocase; classtype:trojan-activity; sid:100001188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.113.209.187",nocase; classtype:trojan-activity; sid:100001189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.108.244",nocase; classtype:trojan-activity; sid:100001190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.43.47",nocase; classtype:trojan-activity; sid:100001191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.60.73",nocase; classtype:trojan-activity; sid:100001192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.61.252",nocase; classtype:trojan-activity; sid:100001193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.99.150",nocase; classtype:trojan-activity; sid:100001194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.43.185",nocase; classtype:trojan-activity; sid:100001195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.43.82",nocase; classtype:trojan-activity; sid:100001196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.120.8",nocase; classtype:trojan-activity; sid:100001197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.164.128",nocase; classtype:trojan-activity; sid:100001198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.200.62",nocase; classtype:trojan-activity; sid:100001199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.202.130",nocase; classtype:trojan-activity; sid:100001200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.22",nocase; classtype:trojan-activity; sid:100001201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.46",nocase; classtype:trojan-activity; sid:100001202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.127.106",nocase; classtype:trojan-activity; sid:100001203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.123.205.157",nocase; classtype:trojan-activity; sid:100001204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.123.211.239",nocase; classtype:trojan-activity; sid:100001205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.138.54",nocase; classtype:trojan-activity; sid:100001206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.121.211",nocase; classtype:trojan-activity; sid:100001207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.152.3",nocase; classtype:trojan-activity; sid:100001208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.160.98.250",nocase; classtype:trojan-activity; sid:100001209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.233.0.252",nocase; classtype:trojan-activity; sid:100001210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.235.252.31",nocase; classtype:trojan-activity; sid:100001211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.53.197.62",nocase; classtype:trojan-activity; sid:100001212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.105.104.83",nocase; classtype:trojan-activity; sid:100001213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.105.225.154",nocase; classtype:trojan-activity; sid:100001214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.109.169.45",nocase; classtype:trojan-activity; sid:100001215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.128.152.115",nocase; classtype:trojan-activity; sid:100001216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.144.9.97",nocase; classtype:trojan-activity; sid:100001217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.185.112.19",nocase; classtype:trojan-activity; sid:100001218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.18.203",nocase; classtype:trojan-activity; sid:100001219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.29.191",nocase; classtype:trojan-activity; sid:100001220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.92.207.147",nocase; classtype:trojan-activity; sid:100001221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.164.185.41",nocase; classtype:trojan-activity; sid:100001222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.175.115.10",nocase; classtype:trojan-activity; sid:100001223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.74.149.230",nocase; classtype:trojan-activity; sid:100001224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.106.209.68",nocase; classtype:trojan-activity; sid:100001225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.107.3.8",nocase; classtype:trojan-activity; sid:100001226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.117.2.107",nocase; classtype:trojan-activity; sid:100001227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.172.110.235",nocase; classtype:trojan-activity; sid:100001228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.174.101.41",nocase; classtype:trojan-activity; sid:100001229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.181.10.234",nocase; classtype:trojan-activity; sid:100001230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.112",nocase; classtype:trojan-activity; sid:100001231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.54",nocase; classtype:trojan-activity; sid:100001232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.77",nocase; classtype:trojan-activity; sid:100001233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.93",nocase; classtype:trojan-activity; sid:100001234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.221.3.244",nocase; classtype:trojan-activity; sid:100001235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.222.58.152",nocase; classtype:trojan-activity; sid:100001236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.228.141.74",nocase; classtype:trojan-activity; sid:100001237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.233.186.151",nocase; classtype:trojan-activity; sid:100001238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.26.113.95",nocase; classtype:trojan-activity; sid:100001239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.34.16.231",nocase; classtype:trojan-activity; sid:100001240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.43.19.151",nocase; classtype:trojan-activity; sid:100001241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.55.1.182",nocase; classtype:trojan-activity; sid:100001242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.68.230.207",nocase; classtype:trojan-activity; sid:100001243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.81.157.186",nocase; classtype:trojan-activity; sid:100001244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.185",nocase; classtype:trojan-activity; sid:100001245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.213",nocase; classtype:trojan-activity; sid:100001246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.160",nocase; classtype:trojan-activity; sid:100001247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.161",nocase; classtype:trojan-activity; sid:100001248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.219",nocase; classtype:trojan-activity; sid:100001249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.80",nocase; classtype:trojan-activity; sid:100001250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.151.144.85",nocase; classtype:trojan-activity; sid:100001251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.219.164",nocase; classtype:trojan-activity; sid:100001252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.112",nocase; classtype:trojan-activity; sid:100001253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.77",nocase; classtype:trojan-activity; sid:100001254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.91",nocase; classtype:trojan-activity; sid:100001255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.253.150",nocase; classtype:trojan-activity; sid:100001256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.225.120.173",nocase; classtype:trojan-activity; sid:100001257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.232.44.86",nocase; classtype:trojan-activity; sid:100001258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.28.60.184",nocase; classtype:trojan-activity; sid:100001259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.34.4.40",nocase; classtype:trojan-activity; sid:100001260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.73.188.132",nocase; classtype:trojan-activity; sid:100001261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.12.10.98",nocase; classtype:trojan-activity; sid:100001262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.188.124.229",nocase; classtype:trojan-activity; sid:100001263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.212.200.162",nocase; classtype:trojan-activity; sid:100001264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.85.244.145",nocase; classtype:trojan-activity; sid:100001265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.21.14",nocase; classtype:trojan-activity; sid:100001266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.231.246",nocase; classtype:trojan-activity; sid:100001267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.113.81.17",nocase; classtype:trojan-activity; sid:100001268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.13.179.87",nocase; classtype:trojan-activity; sid:100001269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.138.200.32",nocase; classtype:trojan-activity; sid:100001270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.143.220.152",nocase; classtype:trojan-activity; sid:100001271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.152.41.141",nocase; classtype:trojan-activity; sid:100001272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.178.50",nocase; classtype:trojan-activity; sid:100001273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.242.242.144",nocase; classtype:trojan-activity; sid:100001274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.81.100.83",nocase; classtype:trojan-activity; sid:100001275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.83.202.25",nocase; classtype:trojan-activity; sid:100001276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"189.222.157.241",nocase; classtype:trojan-activity; sid:100001277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.0.42.106",nocase; classtype:trojan-activity; sid:100001278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.109.178.139",nocase; classtype:trojan-activity; sid:100001279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.110.161.252",nocase; classtype:trojan-activity; sid:100001280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.111.151.164",nocase; classtype:trojan-activity; sid:100001281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.119.207.58",nocase; classtype:trojan-activity; sid:100001282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.12.99.194",nocase; classtype:trojan-activity; sid:100001283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.160",nocase; classtype:trojan-activity; sid:100001284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.3",nocase; classtype:trojan-activity; sid:100001285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.37",nocase; classtype:trojan-activity; sid:100001286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.41",nocase; classtype:trojan-activity; sid:100001287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.42",nocase; classtype:trojan-activity; sid:100001288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.15.212",nocase; classtype:trojan-activity; sid:100001289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.20.14",nocase; classtype:trojan-activity; sid:100001290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.147.16.184",nocase; classtype:trojan-activity; sid:100001291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.159.240.9",nocase; classtype:trojan-activity; sid:100001292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.187.55.150",nocase; classtype:trojan-activity; sid:100001293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.210.214.130",nocase; classtype:trojan-activity; sid:100001294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.177.39",nocase; classtype:trojan-activity; sid:100001295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.226.63",nocase; classtype:trojan-activity; sid:100001296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.49.207",nocase; classtype:trojan-activity; sid:100001297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.214.24.194",nocase; classtype:trojan-activity; sid:100001298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.216.140.123",nocase; classtype:trojan-activity; sid:100001299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.65.206.162",nocase; classtype:trojan-activity; sid:100001300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.73.12.149",nocase; classtype:trojan-activity; sid:100001301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.92.4.231",nocase; classtype:trojan-activity; sid:100001302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.135",nocase; classtype:trojan-activity; sid:100001303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.200",nocase; classtype:trojan-activity; sid:100001304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.41.33",nocase; classtype:trojan-activity; sid:100001305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"191.254.225.48",nocase; classtype:trojan-activity; sid:100001306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"191.255.248.220",nocase; classtype:trojan-activity; sid:100001307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.153.57.63",nocase; classtype:trojan-activity; sid:100001308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.210.175.130",nocase; classtype:trojan-activity; sid:100001309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.185.106",nocase; classtype:trojan-activity; sid:100001310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.209.27",nocase; classtype:trojan-activity; sid:100001311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.220.55",nocase; classtype:trojan-activity; sid:100001312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.223.96",nocase; classtype:trojan-activity; sid:100001313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.228.67",nocase; classtype:trojan-activity; sid:100001314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.230.74",nocase; classtype:trojan-activity; sid:100001315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.3.152.166",nocase; classtype:trojan-activity; sid:100001316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.3.73.205",nocase; classtype:trojan-activity; sid:100001317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.99.240.77",nocase; classtype:trojan-activity; sid:100001318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.142.146.25",nocase; classtype:trojan-activity; sid:100001319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.228.135.144",nocase; classtype:trojan-activity; sid:100001320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.113.107.243",nocase; classtype:trojan-activity; sid:100001321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.147.142.230",nocase; classtype:trojan-activity; sid:100001322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.15.36.167",nocase; classtype:trojan-activity; sid:100001323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.15.36.238",nocase; classtype:trojan-activity; sid:100001324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.152.35.139",nocase; classtype:trojan-activity; sid:100001325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.38.20.199",nocase; classtype:trojan-activity; sid:100001326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.139.126.51",nocase; classtype:trojan-activity; sid:100001327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.162.70.104",nocase; classtype:trojan-activity; sid:100001328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.228.231.218",nocase; classtype:trojan-activity; sid:100001329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.24.94.187",nocase; classtype:trojan-activity; sid:100001330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.202.26.182",nocase; classtype:trojan-activity; sid:100001331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.218.48.82",nocase; classtype:trojan-activity; sid:100001332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.166.203",nocase; classtype:trojan-activity; sid:100001333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.50.27.115",nocase; classtype:trojan-activity; sid:100001334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.133.218",nocase; classtype:trojan-activity; sid:100001335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.174.104",nocase; classtype:trojan-activity; sid:100001336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.207.121",nocase; classtype:trojan-activity; sid:100001337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.213.57",nocase; classtype:trojan-activity; sid:100001338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.251.105",nocase; classtype:trojan-activity; sid:100001339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.251.121",nocase; classtype:trojan-activity; sid:100001340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.46.132.132",nocase; classtype:trojan-activity; sid:100001341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.46.201.76",nocase; classtype:trojan-activity; sid:100001342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"199.188.101.109",nocase; classtype:trojan-activity; sid:100001343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1am.co.nz",nocase; classtype:trojan-activity; sid:100001344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.229.89.119",nocase; classtype:trojan-activity; sid:100001345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.239.22.188",nocase; classtype:trojan-activity; sid:100001346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.249.161.188",nocase; classtype:trojan-activity; sid:100001347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.37.149.230",nocase; classtype:trojan-activity; sid:100001348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.37.203.65",nocase; classtype:trojan-activity; sid:100001349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.4.24",nocase; classtype:trojan-activity; sid:100001350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.125.182",nocase; classtype:trojan-activity; sid:100001351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.92.184",nocase; classtype:trojan-activity; sid:100001352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.57.122.107",nocase; classtype:trojan-activity; sid:100001353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.83.152.16",nocase; classtype:trojan-activity; sid:100001354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"20.185.42.197",nocase; classtype:trojan-activity; sid:100001355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.104.150.167",nocase; classtype:trojan-activity; sid:100001356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.105.167.98",nocase; classtype:trojan-activity; sid:100001357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.111.189.70",nocase; classtype:trojan-activity; sid:100001358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.194.4.24",nocase; classtype:trojan-activity; sid:100001359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.2.161.171",nocase; classtype:trojan-activity; sid:100001360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.30.132.50",nocase; classtype:trojan-activity; sid:100001361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.142.147.89",nocase; classtype:trojan-activity; sid:100001362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.170.46.2",nocase; classtype:trojan-activity; sid:100001363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.184.163.170",nocase; classtype:trojan-activity; sid:100001364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.187.102.73",nocase; classtype:trojan-activity; sid:100001365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.200.254.86",nocase; classtype:trojan-activity; sid:100001366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.203.27.37",nocase; classtype:trojan-activity; sid:100001367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.205.12.170",nocase; classtype:trojan-activity; sid:100001368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.107.233.41",nocase; classtype:trojan-activity; sid:100001369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.150.176.100",nocase; classtype:trojan-activity; sid:100001370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.166.217.54",nocase; classtype:trojan-activity; sid:100001371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.175.103.10",nocase; classtype:trojan-activity; sid:100001372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.29.95.12",nocase; classtype:trojan-activity; sid:100001373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.4.124.58",nocase; classtype:trojan-activity; sid:100001374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.176.114",nocase; classtype:trojan-activity; sid:100001375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.191.174",nocase; classtype:trojan-activity; sid:100001376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.74.236.9",nocase; classtype:trojan-activity; sid:100001377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.109.201.243",nocase; classtype:trojan-activity; sid:100001378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.170.123.78",nocase; classtype:trojan-activity; sid:100001379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.204.232.18",nocase; classtype:trojan-activity; sid:100001380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.229.21.56",nocase; classtype:trojan-activity; sid:100001381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.236.190.28",nocase; classtype:trojan-activity; sid:100001382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.238.86.202",nocase; classtype:trojan-activity; sid:100001383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.243.142.132",nocase; classtype:trojan-activity; sid:100001384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.70.166.107",nocase; classtype:trojan-activity; sid:100001385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.77.80.159",nocase; classtype:trojan-activity; sid:100001386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.119.166",nocase; classtype:trojan-activity; sid:100001387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.171.138",nocase; classtype:trojan-activity; sid:100001388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.82.36.34",nocase; classtype:trojan-activity; sid:100001389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.93.6.28",nocase; classtype:trojan-activity; sid:100001390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"204.195.116.171",nocase; classtype:trojan-activity; sid:100001391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"205.185.115.74",nocase; classtype:trojan-activity; sid:100001392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"205.185.116.94",nocase; classtype:trojan-activity; sid:100001393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"205.185.123.217",nocase; classtype:trojan-activity; sid:100001394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"206.248.137.132",nocase; classtype:trojan-activity; sid:100001395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"206.47.41.166",nocase; classtype:trojan-activity; sid:100001396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.180.228.101",nocase; classtype:trojan-activity; sid:100001397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.5.32.6",nocase; classtype:trojan-activity; sid:100001398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"208.163.58.18",nocase; classtype:trojan-activity; sid:100001399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"208.75.27.157",nocase; classtype:trojan-activity; sid:100001400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.39.50",nocase; classtype:trojan-activity; sid:100001401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.190",nocase; classtype:trojan-activity; sid:100001402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.31",nocase; classtype:trojan-activity; sid:100001403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.46.87",nocase; classtype:trojan-activity; sid:100001404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.124.149.19",nocase; classtype:trojan-activity; sid:100001405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.152.122",nocase; classtype:trojan-activity; sid:100001406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.153.142",nocase; classtype:trojan-activity; sid:100001407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.234.93",nocase; classtype:trojan-activity; sid:100001408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.237.70",nocase; classtype:trojan-activity; sid:100001409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.245.109",nocase; classtype:trojan-activity; sid:100001410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.68.242.114",nocase; classtype:trojan-activity; sid:100001411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.96.116.236",nocase; classtype:trojan-activity; sid:100001412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.116.220.37",nocase; classtype:trojan-activity; sid:100001413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.132.204",nocase; classtype:trojan-activity; sid:100001414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.75.220",nocase; classtype:trojan-activity; sid:100001415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.200.160.239",nocase; classtype:trojan-activity; sid:100001416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.204.215.157",nocase; classtype:trojan-activity; sid:100001417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.66.179",nocase; classtype:trojan-activity; sid:100001418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.93.93",nocase; classtype:trojan-activity; sid:100001419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.216.66.105",nocase; classtype:trojan-activity; sid:100001420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.114.96",nocase; classtype:trojan-activity; sid:100001421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.120.13",nocase; classtype:trojan-activity; sid:100001422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.246.137",nocase; classtype:trojan-activity; sid:100001423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.238.83.238",nocase; classtype:trojan-activity; sid:100001424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.247.113.49",nocase; classtype:trojan-activity; sid:100001425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.247.5.96",nocase; classtype:trojan-activity; sid:100001426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.32.122.110",nocase; classtype:trojan-activity; sid:100001427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.122.86.105",nocase; classtype:trojan-activity; sid:100001428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.143.227.22",nocase; classtype:trojan-activity; sid:100001429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.156.215.178",nocase; classtype:trojan-activity; sid:100001430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.46.197.114",nocase; classtype:trojan-activity; sid:100001431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.56.197.230",nocase; classtype:trojan-activity; sid:100001432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.8.251.211",nocase; classtype:trojan-activity; sid:100001433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.123.206.197",nocase; classtype:trojan-activity; sid:100001434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.135.178.253",nocase; classtype:trojan-activity; sid:100001435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.14.173.117",nocase; classtype:trojan-activity; sid:100001436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.149.182.113",nocase; classtype:trojan-activity; sid:100001437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.149.190.193",nocase; classtype:trojan-activity; sid:100001438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.12",nocase; classtype:trojan-activity; sid:100001439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.99",nocase; classtype:trojan-activity; sid:100001440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.135",nocase; classtype:trojan-activity; sid:100001441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.20",nocase; classtype:trojan-activity; sid:100001442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.237",nocase; classtype:trojan-activity; sid:100001443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.6",nocase; classtype:trojan-activity; sid:100001444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.114.165",nocase; classtype:trojan-activity; sid:100001445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.105",nocase; classtype:trojan-activity; sid:100001446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.11",nocase; classtype:trojan-activity; sid:100001447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.15",nocase; classtype:trojan-activity; sid:100001448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.30",nocase; classtype:trojan-activity; sid:100001449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.71",nocase; classtype:trojan-activity; sid:100001450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.192",nocase; classtype:trojan-activity; sid:100001451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.117.151",nocase; classtype:trojan-activity; sid:100001452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.238",nocase; classtype:trojan-activity; sid:100001453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.65",nocase; classtype:trojan-activity; sid:100001454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.119.236",nocase; classtype:trojan-activity; sid:100001455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.175",nocase; classtype:trojan-activity; sid:100001456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.7",nocase; classtype:trojan-activity; sid:100001457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.107",nocase; classtype:trojan-activity; sid:100001458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.46",nocase; classtype:trojan-activity; sid:100001459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.189.178.163",nocase; classtype:trojan-activity; sid:100001460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.240.218.15",nocase; classtype:trojan-activity; sid:100001461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.249.156.189",nocase; classtype:trojan-activity; sid:100001462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.27.8.6",nocase; classtype:trojan-activity; sid:100001463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.254.52",nocase; classtype:trojan-activity; sid:100001464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.255.36",nocase; classtype:trojan-activity; sid:100001465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.255.84",nocase; classtype:trojan-activity; sid:100001466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.127.185.150",nocase; classtype:trojan-activity; sid:100001467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.158.238.236",nocase; classtype:trojan-activity; sid:100001468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.170.240.98",nocase; classtype:trojan-activity; sid:100001469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.183.54.169",nocase; classtype:trojan-activity; sid:100001470; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.36.12.98",nocase; classtype:trojan-activity; sid:100001471; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"217.11.75.162",nocase; classtype:trojan-activity; sid:100001472; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.12.181.110",nocase; classtype:trojan-activity; sid:100001473; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.2.40.34",nocase; classtype:trojan-activity; sid:100001474; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.234.165.18",nocase; classtype:trojan-activity; sid:100001475; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.238.246.3",nocase; classtype:trojan-activity; sid:100001476; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.28.160.174",nocase; classtype:trojan-activity; sid:100001477; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.207.119",nocase; classtype:trojan-activity; sid:100001478; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.227.133",nocase; classtype:trojan-activity; sid:100001479; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.68.35",nocase; classtype:trojan-activity; sid:100001480; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.81.81",nocase; classtype:trojan-activity; sid:100001481; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.56.93.129",nocase; classtype:trojan-activity; sid:100001482; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.58.92.253",nocase; classtype:trojan-activity; sid:100001483; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.59.116.203",nocase; classtype:trojan-activity; sid:100001484; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.72.207.116",nocase; classtype:trojan-activity; sid:100001485; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.79.103.159",nocase; classtype:trojan-activity; sid:100001486; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.93.102.63",nocase; classtype:trojan-activity; sid:100001487; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.93.102.75",nocase; classtype:trojan-activity; sid:100001488; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.102.14",nocase; classtype:trojan-activity; sid:100001489; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.11.207",nocase; classtype:trojan-activity; sid:100001490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.12.85",nocase; classtype:trojan-activity; sid:100001491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.26.190",nocase; classtype:trojan-activity; sid:100001492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.29.165",nocase; classtype:trojan-activity; sid:100001493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.186.18",nocase; classtype:trojan-activity; sid:100001494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.139.165",nocase; classtype:trojan-activity; sid:100001495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.150.91",nocase; classtype:trojan-activity; sid:100001496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.214.235",nocase; classtype:trojan-activity; sid:100001497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.50.106",nocase; classtype:trojan-activity; sid:100001498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.241.6.180",nocase; classtype:trojan-activity; sid:100001499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.1.148",nocase; classtype:trojan-activity; sid:100001500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.1.84",nocase; classtype:trojan-activity; sid:100001501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.163.7",nocase; classtype:trojan-activity; sid:100001502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.171.144",nocase; classtype:trojan-activity; sid:100001503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.245.63",nocase; classtype:trojan-activity; sid:100001504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.5.140",nocase; classtype:trojan-activity; sid:100001505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.69.71.186",nocase; classtype:trojan-activity; sid:100001506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.80.217.209",nocase; classtype:trojan-activity; sid:100001507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.85.145.194",nocase; classtype:trojan-activity; sid:100001508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"21robo.com",nocase; classtype:trojan-activity; sid:100001509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.118.168.155",nocase; classtype:trojan-activity; sid:100001510; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.126.237.74",nocase; classtype:trojan-activity; sid:100001511; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.200.22.163",nocase; classtype:trojan-activity; sid:100001512; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.247.91.17",nocase; classtype:trojan-activity; sid:100001513; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.71.239.115",nocase; classtype:trojan-activity; sid:100001514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.90.159.188",nocase; classtype:trojan-activity; sid:100001515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.1.144.183",nocase; classtype:trojan-activity; sid:100001516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.124.78.15",nocase; classtype:trojan-activity; sid:100001517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.113.234",nocase; classtype:trojan-activity; sid:100001518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.157.191.178",nocase; classtype:trojan-activity; sid:100001519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.136.213",nocase; classtype:trojan-activity; sid:100001520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.202.232.230",nocase; classtype:trojan-activity; sid:100001521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.130.147",nocase; classtype:trojan-activity; sid:100001522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.251.109",nocase; classtype:trojan-activity; sid:100001523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.116.167",nocase; classtype:trojan-activity; sid:100001524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.172.207",nocase; classtype:trojan-activity; sid:100001525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.184.31",nocase; classtype:trojan-activity; sid:100001526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.252.64",nocase; classtype:trojan-activity; sid:100001527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.8.64",nocase; classtype:trojan-activity; sid:100001528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.232.1.82",nocase; classtype:trojan-activity; sid:100001529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.235.137.36",nocase; classtype:trojan-activity; sid:100001530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.112.125",nocase; classtype:trojan-activity; sid:100001531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.32.88",nocase; classtype:trojan-activity; sid:100001532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.34.43",nocase; classtype:trojan-activity; sid:100001533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.43.223",nocase; classtype:trojan-activity; sid:100001534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.68.16",nocase; classtype:trojan-activity; sid:100001535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.108.17.64",nocase; classtype:trojan-activity; sid:100001536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.118.248.149",nocase; classtype:trojan-activity; sid:100001537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.119.65.145",nocase; classtype:trojan-activity; sid:100001538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.132.125.138",nocase; classtype:trojan-activity; sid:100001539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.103.120",nocase; classtype:trojan-activity; sid:100001540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.67.115",nocase; classtype:trojan-activity; sid:100001541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.9.5",nocase; classtype:trojan-activity; sid:100001542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.148.192",nocase; classtype:trojan-activity; sid:100001543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.211.78",nocase; classtype:trojan-activity; sid:100001544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.17.132",nocase; classtype:trojan-activity; sid:100001545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.237.155",nocase; classtype:trojan-activity; sid:100001546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.17.245",nocase; classtype:trojan-activity; sid:100001547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.162.187.43",nocase; classtype:trojan-activity; sid:100001548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.179.215.189",nocase; classtype:trojan-activity; sid:100001549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.185.116.233",nocase; classtype:trojan-activity; sid:100001550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.187.9.178",nocase; classtype:trojan-activity; sid:100001551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.211.72.66",nocase; classtype:trojan-activity; sid:100001552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.236.85.220",nocase; classtype:trojan-activity; sid:100001553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.238.230.7",nocase; classtype:trojan-activity; sid:100001554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.239.83.232",nocase; classtype:trojan-activity; sid:100001555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.248.64.253",nocase; classtype:trojan-activity; sid:100001556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.92.9.126",nocase; classtype:trojan-activity; sid:100001557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.95.190.20",nocase; classtype:trojan-activity; sid:100001558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.99.171.192",nocase; classtype:trojan-activity; sid:100001559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.131.201.82",nocase; classtype:trojan-activity; sid:100001560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.166.117.210",nocase; classtype:trojan-activity; sid:100001561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.167.118.17",nocase; classtype:trojan-activity; sid:100001562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.225.68",nocase; classtype:trojan-activity; sid:100001563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.234.84",nocase; classtype:trojan-activity; sid:100001564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.5.29",nocase; classtype:trojan-activity; sid:100001565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.73.175",nocase; classtype:trojan-activity; sid:100001566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.115.118.232",nocase; classtype:trojan-activity; sid:100001567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.125.186.135",nocase; classtype:trojan-activity; sid:100001568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.126.120.25",nocase; classtype:trojan-activity; sid:100001569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.228.143.58",nocase; classtype:trojan-activity; sid:100001570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.24.213.121",nocase; classtype:trojan-activity; sid:100001571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.149.13",nocase; classtype:trojan-activity; sid:100001572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.21.167",nocase; classtype:trojan-activity; sid:100001573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.95.89.21",nocase; classtype:trojan-activity; sid:100001574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.103.74.180",nocase; classtype:trojan-activity; sid:100001575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.11.141.134",nocase; classtype:trojan-activity; sid:100001576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.119.158.74",nocase; classtype:trojan-activity; sid:100001577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.137.147.95",nocase; classtype:trojan-activity; sid:100001578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.137.233.132",nocase; classtype:trojan-activity; sid:100001579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.152.235.88",nocase; classtype:trojan-activity; sid:100001580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.158.25.98",nocase; classtype:trojan-activity; sid:100001581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.176.206.12",nocase; classtype:trojan-activity; sid:100001582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.184.1.41",nocase; classtype:trojan-activity; sid:100001583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.192.191.109",nocase; classtype:trojan-activity; sid:100001584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.225.114.161",nocase; classtype:trojan-activity; sid:100001585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.227.190.78",nocase; classtype:trojan-activity; sid:100001586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.35.245.52",nocase; classtype:trojan-activity; sid:100001587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.39.181.18",nocase; classtype:trojan-activity; sid:100001588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.39.34.242",nocase; classtype:trojan-activity; sid:100001589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.42.229.143",nocase; classtype:trojan-activity; sid:100001590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.45.4.1",nocase; classtype:trojan-activity; sid:100001591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.51.91.113",nocase; classtype:trojan-activity; sid:100001592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.53.163.10",nocase; classtype:trojan-activity; sid:100001593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.53.163.9",nocase; classtype:trojan-activity; sid:100001594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.89.140.190",nocase; classtype:trojan-activity; sid:100001595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.1.245.16",nocase; classtype:trojan-activity; sid:100001596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.1.245.7",nocase; classtype:trojan-activity; sid:100001597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.105.106.201",nocase; classtype:trojan-activity; sid:100001598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.105.152.107",nocase; classtype:trojan-activity; sid:100001599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.116.84.57",nocase; classtype:trojan-activity; sid:100001600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.14.81.201",nocase; classtype:trojan-activity; sid:100001601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.141.218.17",nocase; classtype:trojan-activity; sid:100001602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.147.29.52",nocase; classtype:trojan-activity; sid:100001603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.147.40.128",nocase; classtype:trojan-activity; sid:100001604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.184.251.135",nocase; classtype:trojan-activity; sid:100001605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.193.196.190",nocase; classtype:trojan-activity; sid:100001606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.193.217.210",nocase; classtype:trojan-activity; sid:100001607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.149.142",nocase; classtype:trojan-activity; sid:100001608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.159.98",nocase; classtype:trojan-activity; sid:100001609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.192.66",nocase; classtype:trojan-activity; sid:100001610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.210.20",nocase; classtype:trojan-activity; sid:100001611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.22.217",nocase; classtype:trojan-activity; sid:100001612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.23.215",nocase; classtype:trojan-activity; sid:100001613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.232.65",nocase; classtype:trojan-activity; sid:100001614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.3.194",nocase; classtype:trojan-activity; sid:100001615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.34.48",nocase; classtype:trojan-activity; sid:100001616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.110.211",nocase; classtype:trojan-activity; sid:100001617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.140.229",nocase; classtype:trojan-activity; sid:100001618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.32.146",nocase; classtype:trojan-activity; sid:100001619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.201.183.149",nocase; classtype:trojan-activity; sid:100001620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.202.182.201",nocase; classtype:trojan-activity; sid:100001621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.102.12",nocase; classtype:trojan-activity; sid:100001622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.116.86",nocase; classtype:trojan-activity; sid:100001623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.154.105",nocase; classtype:trojan-activity; sid:100001624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.165.138",nocase; classtype:trojan-activity; sid:100001625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.185.42",nocase; classtype:trojan-activity; sid:100001626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.213.79",nocase; classtype:trojan-activity; sid:100001627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.255.42",nocase; classtype:trojan-activity; sid:100001628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.28.115",nocase; classtype:trojan-activity; sid:100001629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.4.188",nocase; classtype:trojan-activity; sid:100001630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.68.144",nocase; classtype:trojan-activity; sid:100001631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.7.141",nocase; classtype:trojan-activity; sid:100001632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.87.75",nocase; classtype:trojan-activity; sid:100001633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.94.134",nocase; classtype:trojan-activity; sid:100001634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.204.253.74",nocase; classtype:trojan-activity; sid:100001635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.205.178.110",nocase; classtype:trojan-activity; sid:100001636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.136.101",nocase; classtype:trojan-activity; sid:100001637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.154.122",nocase; classtype:trojan-activity; sid:100001638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.80.209",nocase; classtype:trojan-activity; sid:100001639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.151.126",nocase; classtype:trojan-activity; sid:100001640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.155.31",nocase; classtype:trojan-activity; sid:100001641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.170.203",nocase; classtype:trojan-activity; sid:100001642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.119.27",nocase; classtype:trojan-activity; sid:100001643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.152.10",nocase; classtype:trojan-activity; sid:100001644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.160.177",nocase; classtype:trojan-activity; sid:100001645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.164.18",nocase; classtype:trojan-activity; sid:100001646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.237.105",nocase; classtype:trojan-activity; sid:100001647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.247.130",nocase; classtype:trojan-activity; sid:100001648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.25.59",nocase; classtype:trojan-activity; sid:100001649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.34.2",nocase; classtype:trojan-activity; sid:100001650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.92.64",nocase; classtype:trojan-activity; sid:100001651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.208.122",nocase; classtype:trojan-activity; sid:100001652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.231.15",nocase; classtype:trojan-activity; sid:100001653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.107.125",nocase; classtype:trojan-activity; sid:100001654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.172.245",nocase; classtype:trojan-activity; sid:100001655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.234.28",nocase; classtype:trojan-activity; sid:100001656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.236.134",nocase; classtype:trojan-activity; sid:100001657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.44.19",nocase; classtype:trojan-activity; sid:100001658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.63.243",nocase; classtype:trojan-activity; sid:100001659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.104.201",nocase; classtype:trojan-activity; sid:100001660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.109.58",nocase; classtype:trojan-activity; sid:100001661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.175.208",nocase; classtype:trojan-activity; sid:100001662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.255.202",nocase; classtype:trojan-activity; sid:100001663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.66.112",nocase; classtype:trojan-activity; sid:100001664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.84.74",nocase; classtype:trojan-activity; sid:100001665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.214.37.129",nocase; classtype:trojan-activity; sid:100001666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.139.242",nocase; classtype:trojan-activity; sid:100001667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.190.172",nocase; classtype:trojan-activity; sid:100001668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.212.209",nocase; classtype:trojan-activity; sid:100001669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.253.149",nocase; classtype:trojan-activity; sid:100001670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.34.242",nocase; classtype:trojan-activity; sid:100001671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.71.243",nocase; classtype:trojan-activity; sid:100001672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.98.242",nocase; classtype:trojan-activity; sid:100001673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.128.156",nocase; classtype:trojan-activity; sid:100001674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.131.66",nocase; classtype:trojan-activity; sid:100001675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.144.66",nocase; classtype:trojan-activity; sid:100001676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.197.193",nocase; classtype:trojan-activity; sid:100001677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.225.28",nocase; classtype:trojan-activity; sid:100001678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.227.95",nocase; classtype:trojan-activity; sid:100001679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.234.98",nocase; classtype:trojan-activity; sid:100001680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.133.53",nocase; classtype:trojan-activity; sid:100001681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.191.58",nocase; classtype:trojan-activity; sid:100001682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.248.121",nocase; classtype:trojan-activity; sid:100001683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.132.71",nocase; classtype:trojan-activity; sid:100001684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.151.83",nocase; classtype:trojan-activity; sid:100001685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.160.112",nocase; classtype:trojan-activity; sid:100001686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.176.72",nocase; classtype:trojan-activity; sid:100001687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.192.223",nocase; classtype:trojan-activity; sid:100001688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.83.244",nocase; classtype:trojan-activity; sid:100001689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.20.66",nocase; classtype:trojan-activity; sid:100001690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.249.0",nocase; classtype:trojan-activity; sid:100001691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.85.168",nocase; classtype:trojan-activity; sid:100001692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.221.239.223",nocase; classtype:trojan-activity; sid:100001693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.241.223",nocase; classtype:trojan-activity; sid:100001694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.249.210",nocase; classtype:trojan-activity; sid:100001695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.76.80",nocase; classtype:trojan-activity; sid:100001696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.223.242.164",nocase; classtype:trojan-activity; sid:100001697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.24.28.134",nocase; classtype:trojan-activity; sid:100001698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.129.198",nocase; classtype:trojan-activity; sid:100001699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.154.13",nocase; classtype:trojan-activity; sid:100001700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.16.145",nocase; classtype:trojan-activity; sid:100001701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.2.30",nocase; classtype:trojan-activity; sid:100001702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.212.124",nocase; classtype:trojan-activity; sid:100001703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.58.5",nocase; classtype:trojan-activity; sid:100001704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.237.129",nocase; classtype:trojan-activity; sid:100001705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.43.117.98",nocase; classtype:trojan-activity; sid:100001706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.0.98.131",nocase; classtype:trojan-activity; sid:100001707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.11.51.57",nocase; classtype:trojan-activity; sid:100001708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.13.23.180",nocase; classtype:trojan-activity; sid:100001709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.124.130",nocase; classtype:trojan-activity; sid:100001710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.179.83",nocase; classtype:trojan-activity; sid:100001711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.184.59",nocase; classtype:trojan-activity; sid:100001712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.191.243",nocase; classtype:trojan-activity; sid:100001713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.194.67",nocase; classtype:trojan-activity; sid:100001714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.216.132",nocase; classtype:trojan-activity; sid:100001715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.219.28",nocase; classtype:trojan-activity; sid:100001716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.24.115",nocase; classtype:trojan-activity; sid:100001717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.30.65",nocase; classtype:trojan-activity; sid:100001718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.63.203",nocase; classtype:trojan-activity; sid:100001719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.65.233",nocase; classtype:trojan-activity; sid:100001720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.79.66",nocase; classtype:trojan-activity; sid:100001721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.94.16",nocase; classtype:trojan-activity; sid:100001722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.179.201.26",nocase; classtype:trojan-activity; sid:100001723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.195.84.250",nocase; classtype:trojan-activity; sid:100001724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.177",nocase; classtype:trojan-activity; sid:100001725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.69",nocase; classtype:trojan-activity; sid:100001726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.28.7.159",nocase; classtype:trojan-activity; sid:100001727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.30.119.23",nocase; classtype:trojan-activity; sid:100001728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32.208.157.193",nocase; classtype:trojan-activity; sid:100001729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32792.prolocksmithwinterpark.com",nocase; classtype:trojan-activity; sid:100001730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"35.184.169.169",nocase; classtype:trojan-activity; sid:100001731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.107.209.10",nocase; classtype:trojan-activity; sid:100001732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.108.231.218",nocase; classtype:trojan-activity; sid:100001733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.248.228.64",nocase; classtype:trojan-activity; sid:100001734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.250.203.246",nocase; classtype:trojan-activity; sid:100001735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.157.225",nocase; classtype:trojan-activity; sid:100001736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.18.18",nocase; classtype:trojan-activity; sid:100001737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.51.244",nocase; classtype:trojan-activity; sid:100001738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.255.90.219",nocase; classtype:trojan-activity; sid:100001739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.33.160.167",nocase; classtype:trojan-activity; sid:100001740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.34.150.236",nocase; classtype:trojan-activity; sid:100001741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.105.159",nocase; classtype:trojan-activity; sid:100001742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.111.203",nocase; classtype:trojan-activity; sid:100001743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.139.36",nocase; classtype:trojan-activity; sid:100001744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.89.18.133",nocase; classtype:trojan-activity; sid:100001745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360.lcy2zzx.pw",nocase; classtype:trojan-activity; sid:100001746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360down7.miiyun.cn",nocase; classtype:trojan-activity; sid:100001747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.222.98.51",nocase; classtype:trojan-activity; sid:100001748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.233.60.68",nocase; classtype:trojan-activity; sid:100001749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.179.221",nocase; classtype:trojan-activity; sid:100001750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.180.172",nocase; classtype:trojan-activity; sid:100001751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.44.238.35",nocase; classtype:trojan-activity; sid:100001752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.49.230.177",nocase; classtype:trojan-activity; sid:100001753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.14.36",nocase; classtype:trojan-activity; sid:100001754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.14.52",nocase; classtype:trojan-activity; sid:100001755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.230.61",nocase; classtype:trojan-activity; sid:100001756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"38.77.14.237",nocase; classtype:trojan-activity; sid:100001757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.245.254",nocase; classtype:trojan-activity; sid:100001758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.98.136",nocase; classtype:trojan-activity; sid:100001759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.117.31.162",nocase; classtype:trojan-activity; sid:100001760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.162.104.119",nocase; classtype:trojan-activity; sid:100001761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.196.34",nocase; classtype:trojan-activity; sid:100001762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.59.160",nocase; classtype:trojan-activity; sid:100001763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.66.44.109",nocase; classtype:trojan-activity; sid:100001764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.104.83",nocase; classtype:trojan-activity; sid:100001765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.125.186",nocase; classtype:trojan-activity; sid:100001766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.146.60",nocase; classtype:trojan-activity; sid:100001767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.148.163",nocase; classtype:trojan-activity; sid:100001768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.206.228",nocase; classtype:trojan-activity; sid:100001769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.124.76",nocase; classtype:trojan-activity; sid:100001770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.171.125",nocase; classtype:trojan-activity; sid:100001771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.249.255",nocase; classtype:trojan-activity; sid:100001772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.60.61",nocase; classtype:trojan-activity; sid:100001773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.167.202",nocase; classtype:trojan-activity; sid:100001774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.67.64",nocase; classtype:trojan-activity; sid:100001775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.10.198",nocase; classtype:trojan-activity; sid:100001776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.163.231",nocase; classtype:trojan-activity; sid:100001777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.168.234",nocase; classtype:trojan-activity; sid:100001778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.203.225",nocase; classtype:trojan-activity; sid:100001779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.237.84",nocase; classtype:trojan-activity; sid:100001780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.132.170",nocase; classtype:trojan-activity; sid:100001781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.194.65",nocase; classtype:trojan-activity; sid:100001782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.235.122",nocase; classtype:trojan-activity; sid:100001783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.33.191",nocase; classtype:trojan-activity; sid:100001784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.78.251",nocase; classtype:trojan-activity; sid:100001785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.113.201",nocase; classtype:trojan-activity; sid:100001786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.114.45",nocase; classtype:trojan-activity; sid:100001787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.14.27",nocase; classtype:trojan-activity; sid:100001788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.150.203",nocase; classtype:trojan-activity; sid:100001789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.197.81",nocase; classtype:trojan-activity; sid:100001790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.209.209",nocase; classtype:trojan-activity; sid:100001791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.48.213",nocase; classtype:trojan-activity; sid:100001792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.63.152",nocase; classtype:trojan-activity; sid:100001793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.94.189",nocase; classtype:trojan-activity; sid:100001794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.163.188",nocase; classtype:trojan-activity; sid:100001795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.166.31",nocase; classtype:trojan-activity; sid:100001796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.218.46",nocase; classtype:trojan-activity; sid:100001797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.91.244",nocase; classtype:trojan-activity; sid:100001798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.93.171",nocase; classtype:trojan-activity; sid:100001799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.127.214",nocase; classtype:trojan-activity; sid:100001800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.18.140",nocase; classtype:trojan-activity; sid:100001801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.191.137",nocase; classtype:trojan-activity; sid:100001802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.205.255",nocase; classtype:trojan-activity; sid:100001803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.24.54",nocase; classtype:trojan-activity; sid:100001804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.36.151",nocase; classtype:trojan-activity; sid:100001805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.37.182",nocase; classtype:trojan-activity; sid:100001806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.251.0",nocase; classtype:trojan-activity; sid:100001807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.27.15",nocase; classtype:trojan-activity; sid:100001808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.29.231",nocase; classtype:trojan-activity; sid:100001809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.70.88",nocase; classtype:trojan-activity; sid:100001810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.83.94.11",nocase; classtype:trojan-activity; sid:100001811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.115.152",nocase; classtype:trojan-activity; sid:100001812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.85.54.191",nocase; classtype:trojan-activity; sid:100001813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.85.54.4",nocase; classtype:trojan-activity; sid:100001814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.129.233",nocase; classtype:trojan-activity; sid:100001815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.170.209",nocase; classtype:trojan-activity; sid:100001816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.211.20",nocase; classtype:trojan-activity; sid:100001817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.234.187",nocase; classtype:trojan-activity; sid:100001818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.63.58",nocase; classtype:trojan-activity; sid:100001819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.93.109",nocase; classtype:trojan-activity; sid:100001820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.155.96",nocase; classtype:trojan-activity; sid:100001821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.233.131",nocase; classtype:trojan-activity; sid:100001822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.67.238",nocase; classtype:trojan-activity; sid:100001823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.108.109",nocase; classtype:trojan-activity; sid:100001824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.145.11",nocase; classtype:trojan-activity; sid:100001825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.146.198",nocase; classtype:trojan-activity; sid:100001826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.146.36",nocase; classtype:trojan-activity; sid:100001827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.63.23",nocase; classtype:trojan-activity; sid:100001828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.90.86.212",nocase; classtype:trojan-activity; sid:100001829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"40.88.2.151",nocase; classtype:trojan-activity; sid:100001830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.139.209.46",nocase; classtype:trojan-activity; sid:100001831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.165.130.43",nocase; classtype:trojan-activity; sid:100001832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.190.63.174",nocase; classtype:trojan-activity; sid:100001833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.193.192.100",nocase; classtype:trojan-activity; sid:100001834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.219.185.171",nocase; classtype:trojan-activity; sid:100001835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.226.60.115",nocase; classtype:trojan-activity; sid:100001836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.72.203.82",nocase; classtype:trojan-activity; sid:100001837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.169",nocase; classtype:trojan-activity; sid:100001838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.23",nocase; classtype:trojan-activity; sid:100001839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.27",nocase; classtype:trojan-activity; sid:100001840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.38",nocase; classtype:trojan-activity; sid:100001841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.202.101.199",nocase; classtype:trojan-activity; sid:100001842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.43.161",nocase; classtype:trojan-activity; sid:100001843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.65.104",nocase; classtype:trojan-activity; sid:100001844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.82.176",nocase; classtype:trojan-activity; sid:100001845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.180.147",nocase; classtype:trojan-activity; sid:100001846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.239.26.122",nocase; classtype:trojan-activity; sid:100001847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.56.15.227",nocase; classtype:trojan-activity; sid:100001848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.61.99.155",nocase; classtype:trojan-activity; sid:100001849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.82.217.241",nocase; classtype:trojan-activity; sid:100001850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.84.37.198",nocase; classtype:trojan-activity; sid:100001851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.241.106.183",nocase; classtype:trojan-activity; sid:100001852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.241.108.134",nocase; classtype:trojan-activity; sid:100001853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.252.8.94",nocase; classtype:trojan-activity; sid:100001854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.115.172.148",nocase; classtype:trojan-activity; sid:100001855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.1.242",nocase; classtype:trojan-activity; sid:100001856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.203.192",nocase; classtype:trojan-activity; sid:100001857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.135.134.228",nocase; classtype:trojan-activity; sid:100001858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.204",nocase; classtype:trojan-activity; sid:100001859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.141.84.184",nocase; classtype:trojan-activity; sid:100001860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.118",nocase; classtype:trojan-activity; sid:100001861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.135",nocase; classtype:trojan-activity; sid:100001862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.139",nocase; classtype:trojan-activity; sid:100001863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.196",nocase; classtype:trojan-activity; sid:100001864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.213",nocase; classtype:trojan-activity; sid:100001865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.242",nocase; classtype:trojan-activity; sid:100001866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.27",nocase; classtype:trojan-activity; sid:100001867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.65",nocase; classtype:trojan-activity; sid:100001868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.47",nocase; classtype:trojan-activity; sid:100001869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.94",nocase; classtype:trojan-activity; sid:100001870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.164.140.130",nocase; classtype:trojan-activity; sid:100001871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.165.215.19",nocase; classtype:trojan-activity; sid:100001872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.151",nocase; classtype:trojan-activity; sid:100001873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.22",nocase; classtype:trojan-activity; sid:100001874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.248",nocase; classtype:trojan-activity; sid:100001875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.110.99",nocase; classtype:trojan-activity; sid:100001876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.22.209.58",nocase; classtype:trojan-activity; sid:100001877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.229.53.115",nocase; classtype:trojan-activity; sid:100001878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.23.22.186",nocase; classtype:trojan-activity; sid:100001879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.248.194.48",nocase; classtype:trojan-activity; sid:100001880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.27.253.137",nocase; classtype:trojan-activity; sid:100001881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.51.104.59",nocase; classtype:trojan-activity; sid:100001882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.6.24.251",nocase; classtype:trojan-activity; sid:100001883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.81.235.31",nocase; classtype:trojan-activity; sid:100001884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.85.90.131",nocase; classtype:trojan-activity; sid:100001885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.85.90.179",nocase; classtype:trojan-activity; sid:100001886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.85.90.203",nocase; classtype:trojan-activity; sid:100001887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.9.148.37",nocase; classtype:trojan-activity; sid:100001888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.92.108.125",nocase; classtype:trojan-activity; sid:100001889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.95.169.153",nocase; classtype:trojan-activity; sid:100001890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.117.42.29",nocase; classtype:trojan-activity; sid:100001891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.172.75.231",nocase; classtype:trojan-activity; sid:100001892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.182.173.246",nocase; classtype:trojan-activity; sid:100001893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.182.173.247",nocase; classtype:trojan-activity; sid:100001894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.20.63.218",nocase; classtype:trojan-activity; sid:100001895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.214.27.4",nocase; classtype:trojan-activity; sid:100001896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.24.130.254",nocase; classtype:trojan-activity; sid:100001897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.241.120.165",nocase; classtype:trojan-activity; sid:100001898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.243.179.115",nocase; classtype:trojan-activity; sid:100001899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.249.33.79",nocase; classtype:trojan-activity; sid:100001900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.25.242.211",nocase; classtype:trojan-activity; sid:100001901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.118.86",nocase; classtype:trojan-activity; sid:100001902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.86.128",nocase; classtype:trojan-activity; sid:100001903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.97.76.242",nocase; classtype:trojan-activity; sid:100001904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.103.219.77",nocase; classtype:trojan-activity; sid:100001905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.145.152.26",nocase; classtype:trojan-activity; sid:100001906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.151.23.172",nocase; classtype:trojan-activity; sid:100001907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.157.97.71",nocase; classtype:trojan-activity; sid:100001908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.16.131.51",nocase; classtype:trojan-activity; sid:100001909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.21.202.98",nocase; classtype:trojan-activity; sid:100001910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.46.231.38",nocase; classtype:trojan-activity; sid:100001911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.162.113",nocase; classtype:trojan-activity; sid:100001912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.87.36",nocase; classtype:trojan-activity; sid:100001913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.143.43.93",nocase; classtype:trojan-activity; sid:100001914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.156.35.166",nocase; classtype:trojan-activity; sid:100001915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.158.201.200",nocase; classtype:trojan-activity; sid:100001916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.20.121",nocase; classtype:trojan-activity; sid:100001917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.21.3",nocase; classtype:trojan-activity; sid:100001918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.174.182.99",nocase; classtype:trojan-activity; sid:100001919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.170.49",nocase; classtype:trojan-activity; sid:100001920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.178.183",nocase; classtype:trojan-activity; sid:100001921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.179.129",nocase; classtype:trojan-activity; sid:100001922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.68.221.252",nocase; classtype:trojan-activity; sid:100001923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.188.62.111",nocase; classtype:trojan-activity; sid:100001924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.2.70.50",nocase; classtype:trojan-activity; sid:100001925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.42.37.74",nocase; classtype:trojan-activity; sid:100001926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.53.146.179",nocase; classtype:trojan-activity; sid:100001927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.79.75.210",nocase; classtype:trojan-activity; sid:100001928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.95.226.154",nocase; classtype:trojan-activity; sid:100001929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.115.174.102",nocase; classtype:trojan-activity; sid:100001930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.115.174.106",nocase; classtype:trojan-activity; sid:100001931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.121.91.255",nocase; classtype:trojan-activity; sid:100001932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.252.47.29",nocase; classtype:trojan-activity; sid:100001933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"51.222.56.159",nocase; classtype:trojan-activity; sid:100001934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.114.136",nocase; classtype:trojan-activity; sid:100001935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.180.122",nocase; classtype:trojan-activity; sid:100001936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.114.246.26",nocase; classtype:trojan-activity; sid:100001937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.162.92",nocase; classtype:trojan-activity; sid:100001938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.174.4",nocase; classtype:trojan-activity; sid:100001939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.125.191.4",nocase; classtype:trojan-activity; sid:100001940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.126.247.118",nocase; classtype:trojan-activity; sid:100001941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.141.122.109",nocase; classtype:trojan-activity; sid:100001942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.166.120",nocase; classtype:trojan-activity; sid:100001943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.200.124",nocase; classtype:trojan-activity; sid:100001944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.143.189.75",nocase; classtype:trojan-activity; sid:100001945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.218.67.253",nocase; classtype:trojan-activity; sid:100001946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.22.212.107",nocase; classtype:trojan-activity; sid:100001947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.226.129.29",nocase; classtype:trojan-activity; sid:100001948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.229.194.122",nocase; classtype:trojan-activity; sid:100001949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.230.89.42",nocase; classtype:trojan-activity; sid:100001950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.238.42.192",nocase; classtype:trojan-activity; sid:100001951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.240.147.97",nocase; classtype:trojan-activity; sid:100001952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.241.78.55",nocase; classtype:trojan-activity; sid:100001953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.243.123.212",nocase; classtype:trojan-activity; sid:100001954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.243.126.133",nocase; classtype:trojan-activity; sid:100001955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.243.208.225",nocase; classtype:trojan-activity; sid:100001956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.118.64",nocase; classtype:trojan-activity; sid:100001957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.80.181",nocase; classtype:trojan-activity; sid:100001958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.48.154.143",nocase; classtype:trojan-activity; sid:100001959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.153",nocase; classtype:trojan-activity; sid:100001960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.39",nocase; classtype:trojan-activity; sid:100001961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.76.151.51",nocase; classtype:trojan-activity; sid:100001962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.97.206.33",nocase; classtype:trojan-activity; sid:100001963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.0.211.161",nocase; classtype:trojan-activity; sid:100001964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.102.168.189",nocase; classtype:trojan-activity; sid:100001965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.202.3",nocase; classtype:trojan-activity; sid:100001966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.207.150",nocase; classtype:trojan-activity; sid:100001967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.214.4",nocase; classtype:trojan-activity; sid:100001968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.237.51",nocase; classtype:trojan-activity; sid:100001969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.246.125",nocase; classtype:trojan-activity; sid:100001970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.23.114.97",nocase; classtype:trojan-activity; sid:100001971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.58.117.226",nocase; classtype:trojan-activity; sid:100001972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.10.91.242",nocase; classtype:trojan-activity; sid:100001973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.13.61.12",nocase; classtype:trojan-activity; sid:100001974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.164.130.220",nocase; classtype:trojan-activity; sid:100001975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.175.124.27",nocase; classtype:trojan-activity; sid:100001976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.20.217.142",nocase; classtype:trojan-activity; sid:100001977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.208.135.42",nocase; classtype:trojan-activity; sid:100001978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.122.57",nocase; classtype:trojan-activity; sid:100001979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.186.185",nocase; classtype:trojan-activity; sid:100001980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.216.23",nocase; classtype:trojan-activity; sid:100001981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.233.94",nocase; classtype:trojan-activity; sid:100001982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.6.112",nocase; classtype:trojan-activity; sid:100001983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.100.83",nocase; classtype:trojan-activity; sid:100001984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.111.39",nocase; classtype:trojan-activity; sid:100001985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.202.218",nocase; classtype:trojan-activity; sid:100001986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.206.246",nocase; classtype:trojan-activity; sid:100001987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.218.31",nocase; classtype:trojan-activity; sid:100001988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.220.167",nocase; classtype:trojan-activity; sid:100001989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.254.178",nocase; classtype:trojan-activity; sid:100001990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.162.59",nocase; classtype:trojan-activity; sid:100001991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.83.55",nocase; classtype:trojan-activity; sid:100001992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.195.111",nocase; classtype:trojan-activity; sid:100001993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.177.196",nocase; classtype:trojan-activity; sid:100001994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.86.208",nocase; classtype:trojan-activity; sid:100001995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.223.84.102",nocase; classtype:trojan-activity; sid:100001996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.25.109.240",nocase; classtype:trojan-activity; sid:100001997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.15.104",nocase; classtype:trojan-activity; sid:100001998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.39.88",nocase; classtype:trojan-activity; sid:100001999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.4.72",nocase; classtype:trojan-activity; sid:100002000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.51.127",nocase; classtype:trojan-activity; sid:100002001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.60.174",nocase; classtype:trojan-activity; sid:100002002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.8.81",nocase; classtype:trojan-activity; sid:100002003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.26.104.150",nocase; classtype:trojan-activity; sid:100002004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.10.121",nocase; classtype:trojan-activity; sid:100002005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.8.43",nocase; classtype:trojan-activity; sid:100002006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.99.254",nocase; classtype:trojan-activity; sid:100002007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.164.96.98",nocase; classtype:trojan-activity; sid:100002008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.171.60",nocase; classtype:trojan-activity; sid:100002009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.91.194",nocase; classtype:trojan-activity; sid:100002010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.247.224.66",nocase; classtype:trojan-activity; sid:100002011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.253.94.230",nocase; classtype:trojan-activity; sid:100002012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.3.149.112",nocase; classtype:trojan-activity; sid:100002013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.41.230.161",nocase; classtype:trojan-activity; sid:100002014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.47.220.169",nocase; classtype:trojan-activity; sid:100002015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.103.217",nocase; classtype:trojan-activity; sid:100002016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.199.47",nocase; classtype:trojan-activity; sid:100002017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.207.10",nocase; classtype:trojan-activity; sid:100002018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.30.172",nocase; classtype:trojan-activity; sid:100002019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.9.166",nocase; classtype:trojan-activity; sid:100002020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.9.62",nocase; classtype:trojan-activity; sid:100002021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.99.161",nocase; classtype:trojan-activity; sid:100002022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.102.137",nocase; classtype:trojan-activity; sid:100002023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.117.237",nocase; classtype:trojan-activity; sid:100002024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.220.0",nocase; classtype:trojan-activity; sid:100002025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.103.56",nocase; classtype:trojan-activity; sid:100002026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.64.63",nocase; classtype:trojan-activity; sid:100002027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.180.67",nocase; classtype:trojan-activity; sid:100002028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.181.7",nocase; classtype:trojan-activity; sid:100002029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.57.96.116",nocase; classtype:trojan-activity; sid:100002030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.170.60",nocase; classtype:trojan-activity; sid:100002031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.73.220",nocase; classtype:trojan-activity; sid:100002032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.61.218.23",nocase; classtype:trojan-activity; sid:100002033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.65.172.121",nocase; classtype:trojan-activity; sid:100002034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.0.22",nocase; classtype:trojan-activity; sid:100002035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.104.46",nocase; classtype:trojan-activity; sid:100002036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.110.59",nocase; classtype:trojan-activity; sid:100002037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.195",nocase; classtype:trojan-activity; sid:100002038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.86",nocase; classtype:trojan-activity; sid:100002039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.255.60",nocase; classtype:trojan-activity; sid:100002040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.45.130",nocase; classtype:trojan-activity; sid:100002041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.98.144.75",nocase; classtype:trojan-activity; sid:100002042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.1.98.131",nocase; classtype:trojan-activity; sid:100002043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.141.73.58",nocase; classtype:trojan-activity; sid:100002044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.131.205",nocase; classtype:trojan-activity; sid:100002045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.143.46",nocase; classtype:trojan-activity; sid:100002046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.155.61",nocase; classtype:trojan-activity; sid:100002047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.227.31",nocase; classtype:trojan-activity; sid:100002048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.31.126.33",nocase; classtype:trojan-activity; sid:100002049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.149.66",nocase; classtype:trojan-activity; sid:100002050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.222.98",nocase; classtype:trojan-activity; sid:100002051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.43.207.148",nocase; classtype:trojan-activity; sid:100002052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.90.165.236",nocase; classtype:trojan-activity; sid:100002053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"63.245.122.93",nocase; classtype:trojan-activity; sid:100002054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"64.233.154.99",nocase; classtype:trojan-activity; sid:100002055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.125.128.196",nocase; classtype:trojan-activity; sid:100002056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.21.58.252",nocase; classtype:trojan-activity; sid:100002057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.26.155.131",nocase; classtype:trojan-activity; sid:100002058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.35.61.255",nocase; classtype:trojan-activity; sid:100002059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.229.214.115",nocase; classtype:trojan-activity; sid:100002060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.57.55.210",nocase; classtype:trojan-activity; sid:100002061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.74.7.197",nocase; classtype:trojan-activity; sid:100002062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.97.181.196",nocase; classtype:trojan-activity; sid:100002063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.245.151.203",nocase; classtype:trojan-activity; sid:100002064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.3.169.223",nocase; classtype:trojan-activity; sid:100002065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.8.138.101",nocase; classtype:trojan-activity; sid:100002066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.83.49.234",nocase; classtype:trojan-activity; sid:100002067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.84.138.165",nocase; classtype:trojan-activity; sid:100002068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.148.103.248",nocase; classtype:trojan-activity; sid:100002069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.151.244.128",nocase; classtype:trojan-activity; sid:100002070; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.174.182.226",nocase; classtype:trojan-activity; sid:100002071; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.175.107.153",nocase; classtype:trojan-activity; sid:100002072; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.188.144.143",nocase; classtype:trojan-activity; sid:100002073; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.204.88.29",nocase; classtype:trojan-activity; sid:100002074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.106.84",nocase; classtype:trojan-activity; sid:100002075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.119.241",nocase; classtype:trojan-activity; sid:100002076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.78.33.33",nocase; classtype:trojan-activity; sid:100002077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.115.37.205",nocase; classtype:trojan-activity; sid:100002078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.120.237.255",nocase; classtype:trojan-activity; sid:100002079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.123.245.151",nocase; classtype:trojan-activity; sid:100002080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.124.231.110",nocase; classtype:trojan-activity; sid:100002081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.127.214.47",nocase; classtype:trojan-activity; sid:100002082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.146.232.34",nocase; classtype:trojan-activity; sid:100002083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.165.173.49",nocase; classtype:trojan-activity; sid:100002084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.196.158.227",nocase; classtype:trojan-activity; sid:100002085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.222.157.166",nocase; classtype:trojan-activity; sid:100002086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.229.0.133",nocase; classtype:trojan-activity; sid:100002087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.63.73.234",nocase; classtype:trojan-activity; sid:100002088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.115.194",nocase; classtype:trojan-activity; sid:100002089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.227.186",nocase; classtype:trojan-activity; sid:100002090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.76.240.206",nocase; classtype:trojan-activity; sid:100002091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.115.31.30",nocase; classtype:trojan-activity; sid:100002092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.118.240.88",nocase; classtype:trojan-activity; sid:100002093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.167.10.180",nocase; classtype:trojan-activity; sid:100002094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.236.190.250",nocase; classtype:trojan-activity; sid:100002095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.25.5.105",nocase; classtype:trojan-activity; sid:100002096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.93.129.118",nocase; classtype:trojan-activity; sid:100002097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.127.148.69",nocase; classtype:trojan-activity; sid:100002098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.146.190.91",nocase; classtype:trojan-activity; sid:100002099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.204.63.239",nocase; classtype:trojan-activity; sid:100002100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.29.48.164",nocase; classtype:trojan-activity; sid:100002101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.34.191.213",nocase; classtype:trojan-activity; sid:100002102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.40.234.166",nocase; classtype:trojan-activity; sid:100002103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.106.142",nocase; classtype:trojan-activity; sid:100002104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.2.122",nocase; classtype:trojan-activity; sid:100002105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.235.106",nocase; classtype:trojan-activity; sid:100002106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.47.133.58",nocase; classtype:trojan-activity; sid:100002107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.71.60.69",nocase; classtype:trojan-activity; sid:100002108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.85.106.211",nocase; classtype:trojan-activity; sid:100002109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.17.22.30",nocase; classtype:trojan-activity; sid:100002110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.186.139.38",nocase; classtype:trojan-activity; sid:100002111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.180.98",nocase; classtype:trojan-activity; sid:100002112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.200.62",nocase; classtype:trojan-activity; sid:100002113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.202.249.109",nocase; classtype:trojan-activity; sid:100002114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.214.69.226",nocase; classtype:trojan-activity; sid:100002115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.229.230.118",nocase; classtype:trojan-activity; sid:100002116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.31.40.122",nocase; classtype:trojan-activity; sid:100002117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.204.216.103",nocase; classtype:trojan-activity; sid:100002118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.70.164.42",nocase; classtype:trojan-activity; sid:100002119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.101.1.159",nocase; classtype:trojan-activity; sid:100002120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.108.224.112",nocase; classtype:trojan-activity; sid:100002121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.194.117.165",nocase; classtype:trojan-activity; sid:100002122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.195.115.176",nocase; classtype:trojan-activity; sid:100002123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.199.84.77",nocase; classtype:trojan-activity; sid:100002124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.64.139.223",nocase; classtype:trojan-activity; sid:100002125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.75.165.81",nocase; classtype:trojan-activity; sid:100002126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.127.141.52",nocase; classtype:trojan-activity; sid:100002127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.82.36.220",nocase; classtype:trojan-activity; sid:100002128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.83.102.27",nocase; classtype:trojan-activity; sid:100002129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.99.213.61",nocase; classtype:trojan-activity; sid:100002130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.170.11.82",nocase; classtype:trojan-activity; sid:100002131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.178.22.145",nocase; classtype:trojan-activity; sid:100002132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.217.92.231",nocase; classtype:trojan-activity; sid:100002133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.250.199.133",nocase; classtype:trojan-activity; sid:100002134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.254.129.227",nocase; classtype:trojan-activity; sid:100002135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.84.134.33",nocase; classtype:trojan-activity; sid:100002136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.95.12.137",nocase; classtype:trojan-activity; sid:100002137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.111.182.31",nocase; classtype:trojan-activity; sid:100002138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.237.25.210",nocase; classtype:trojan-activity; sid:100002139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.53.144.46",nocase; classtype:trojan-activity; sid:100002140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.50.153",nocase; classtype:trojan-activity; sid:100002141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.52.220",nocase; classtype:trojan-activity; sid:100002142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.89.203.238",nocase; classtype:trojan-activity; sid:100002143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77st.net",nocase; classtype:trojan-activity; sid:100002144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.145.224.45",nocase; classtype:trojan-activity; sid:100002145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.186.155.18",nocase; classtype:trojan-activity; sid:100002146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.141.144",nocase; classtype:trojan-activity; sid:100002147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.240.125",nocase; classtype:trojan-activity; sid:100002148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.41.200",nocase; classtype:trojan-activity; sid:100002149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.168.64",nocase; classtype:trojan-activity; sid:100002150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.188.141",nocase; classtype:trojan-activity; sid:100002151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.104.157",nocase; classtype:trojan-activity; sid:100002152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.176.163",nocase; classtype:trojan-activity; sid:100002153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.27.157",nocase; classtype:trojan-activity; sid:100002154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.23.172.81",nocase; classtype:trojan-activity; sid:100002155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.8.225.77",nocase; classtype:trojan-activity; sid:100002156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.11.195.121",nocase; classtype:trojan-activity; sid:100002157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.13.49.221",nocase; classtype:trojan-activity; sid:100002158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.130.253.13",nocase; classtype:trojan-activity; sid:100002159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.147.123.48",nocase; classtype:trojan-activity; sid:100002160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.175.42.244",nocase; classtype:trojan-activity; sid:100002161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.7.170.58",nocase; classtype:trojan-activity; sid:100002162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.79.58.94",nocase; classtype:trojan-activity; sid:100002163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.8.70.162",nocase; classtype:trojan-activity; sid:100002164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.9.88.185",nocase; classtype:trojan-activity; sid:100002165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.107.89.207",nocase; classtype:trojan-activity; sid:100002166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.19.101.218",nocase; classtype:trojan-activity; sid:100002167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.211.181.77",nocase; classtype:trojan-activity; sid:100002168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.217.12.7",nocase; classtype:trojan-activity; sid:100002169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.99.128.61",nocase; classtype:trojan-activity; sid:100002170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.136.146.213",nocase; classtype:trojan-activity; sid:100002171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.165.44.109",nocase; classtype:trojan-activity; sid:100002172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.191.40.58",nocase; classtype:trojan-activity; sid:100002173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.213.141.184",nocase; classtype:trojan-activity; sid:100002174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.187.113",nocase; classtype:trojan-activity; sid:100002175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.195.216",nocase; classtype:trojan-activity; sid:100002176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.237.128.200",nocase; classtype:trojan-activity; sid:100002177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.244.219.41",nocase; classtype:trojan-activity; sid:100002178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.246.225.203",nocase; classtype:trojan-activity; sid:100002179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.92.36.96",nocase; classtype:trojan-activity; sid:100002180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.103.108.72",nocase; classtype:trojan-activity; sid:100002181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.135.196.130",nocase; classtype:trojan-activity; sid:100002182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.212.178",nocase; classtype:trojan-activity; sid:100002183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.85.112",nocase; classtype:trojan-activity; sid:100002184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.207.61.194",nocase; classtype:trojan-activity; sid:100002185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.209.250.155",nocase; classtype:trojan-activity; sid:100002186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.211.156.38",nocase; classtype:trojan-activity; sid:100002187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.59.31.181",nocase; classtype:trojan-activity; sid:100002188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.110.252",nocase; classtype:trojan-activity; sid:100002189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.53.77",nocase; classtype:trojan-activity; sid:100002190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.138.72",nocase; classtype:trojan-activity; sid:100002191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.139.92",nocase; classtype:trojan-activity; sid:100002192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.154.214",nocase; classtype:trojan-activity; sid:100002193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.187.109",nocase; classtype:trojan-activity; sid:100002194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.100.54",nocase; classtype:trojan-activity; sid:100002195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.106.65",nocase; classtype:trojan-activity; sid:100002196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.108.172",nocase; classtype:trojan-activity; sid:100002197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.131.158",nocase; classtype:trojan-activity; sid:100002198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.19.42",nocase; classtype:trojan-activity; sid:100002199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.197.254",nocase; classtype:trojan-activity; sid:100002200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.215.149",nocase; classtype:trojan-activity; sid:100002201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.232.68",nocase; classtype:trojan-activity; sid:100002202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.234.195",nocase; classtype:trojan-activity; sid:100002203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.246.96",nocase; classtype:trojan-activity; sid:100002204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.28.57",nocase; classtype:trojan-activity; sid:100002205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.4.57",nocase; classtype:trojan-activity; sid:100002206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.55.84",nocase; classtype:trojan-activity; sid:100002207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.73.245",nocase; classtype:trojan-activity; sid:100002208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.98.51",nocase; classtype:trojan-activity; sid:100002209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.165.237.163",nocase; classtype:trojan-activity; sid:100002210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.147.99",nocase; classtype:trojan-activity; sid:100002211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.218.42",nocase; classtype:trojan-activity; sid:100002212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.242.253.154",nocase; classtype:trojan-activity; sid:100002213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.252.9.37",nocase; classtype:trojan-activity; sid:100002214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.210.219.213",nocase; classtype:trojan-activity; sid:100002215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.212.219.127",nocase; classtype:trojan-activity; sid:100002216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.50.118",nocase; classtype:trojan-activity; sid:100002217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.95.204",nocase; classtype:trojan-activity; sid:100002218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.238.24.35",nocase; classtype:trojan-activity; sid:100002219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.247.83.74",nocase; classtype:trojan-activity; sid:100002220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.254.39.129",nocase; classtype:trojan-activity; sid:100002221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.33.111.227",nocase; classtype:trojan-activity; sid:100002222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.39.248.2",nocase; classtype:trojan-activity; sid:100002223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.40.127.242",nocase; classtype:trojan-activity; sid:100002224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.42.20.217",nocase; classtype:trojan-activity; sid:100002225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com",nocase; classtype:trojan-activity; sid:100002226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.11.216",nocase; classtype:trojan-activity; sid:100002227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.123.251",nocase; classtype:trojan-activity; sid:100002228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.135.187",nocase; classtype:trojan-activity; sid:100002229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.180.33",nocase; classtype:trojan-activity; sid:100002230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.224.141",nocase; classtype:trojan-activity; sid:100002231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.241.2",nocase; classtype:trojan-activity; sid:100002232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.214.149.236",nocase; classtype:trojan-activity; sid:100002233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.64.181.50",nocase; classtype:trojan-activity; sid:100002234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.64.203.204",nocase; classtype:trojan-activity; sid:100002235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.74.215.180",nocase; classtype:trojan-activity; sid:100002236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.130.227",nocase; classtype:trojan-activity; sid:100002237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.195.129",nocase; classtype:trojan-activity; sid:100002238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"86.35.43.220",nocase; classtype:trojan-activity; sid:100002239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.172.19.130",nocase; classtype:trojan-activity; sid:100002240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.61.89.40",nocase; classtype:trojan-activity; sid:100002241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87du.vip",nocase; classtype:trojan-activity; sid:100002242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.208.71",nocase; classtype:trojan-activity; sid:100002243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.219.179",nocase; classtype:trojan-activity; sid:100002244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.225.222.128",nocase; classtype:trojan-activity; sid:100002245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.247.96.19",nocase; classtype:trojan-activity; sid:100002246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.136.231",nocase; classtype:trojan-activity; sid:100002247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.51.139",nocase; classtype:trojan-activity; sid:100002248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.249.244.180",nocase; classtype:trojan-activity; sid:100002249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.204.12",nocase; classtype:trojan-activity; sid:100002250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.226.26",nocase; classtype:trojan-activity; sid:100002251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.240.245",nocase; classtype:trojan-activity; sid:100002252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.254.90",nocase; classtype:trojan-activity; sid:100002253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.122.183.130",nocase; classtype:trojan-activity; sid:100002254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.136.197.170",nocase; classtype:trojan-activity; sid:100002255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.22.152.244",nocase; classtype:trojan-activity; sid:100002256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.29.213.33",nocase; classtype:trojan-activity; sid:100002257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.85.166",nocase; classtype:trojan-activity; sid:100002258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8poieq.bn.files.1drv.com",nocase; classtype:trojan-activity; sid:100002259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"90.152.144.139",nocase; classtype:trojan-activity; sid:100002260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.132.197.39",nocase; classtype:trojan-activity; sid:100002261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.138.215.5",nocase; classtype:trojan-activity; sid:100002262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.177.139.132",nocase; classtype:trojan-activity; sid:100002263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.187.103.32",nocase; classtype:trojan-activity; sid:100002264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.205.173.252",nocase; classtype:trojan-activity; sid:100002265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.212.150.241",nocase; classtype:trojan-activity; sid:100002266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.214.124.141",nocase; classtype:trojan-activity; sid:100002267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.217.104.185",nocase; classtype:trojan-activity; sid:100002268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.233.112.188",nocase; classtype:trojan-activity; sid:100002269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.239.168.83",nocase; classtype:trojan-activity; sid:100002270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.92.16.244",nocase; classtype:trojan-activity; sid:100002271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.98.4.181",nocase; classtype:trojan-activity; sid:100002272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.114.191.82",nocase; classtype:trojan-activity; sid:100002273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.241.78.114",nocase; classtype:trojan-activity; sid:100002274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.27.246.202",nocase; classtype:trojan-activity; sid:100002275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.83.62.139",nocase; classtype:trojan-activity; sid:100002276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.85.18.138",nocase; classtype:trojan-activity; sid:100002277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.159.169.190",nocase; classtype:trojan-activity; sid:100002278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.21.224.154",nocase; classtype:trojan-activity; sid:100002279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.39.115.176",nocase; classtype:trojan-activity; sid:100002280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.39.79.41",nocase; classtype:trojan-activity; sid:100002281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.137.16",nocase; classtype:trojan-activity; sid:100002282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.182.249",nocase; classtype:trojan-activity; sid:100002283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.206.56",nocase; classtype:trojan-activity; sid:100002284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.57.43.233",nocase; classtype:trojan-activity; sid:100002285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.73.99.102",nocase; classtype:trojan-activity; sid:100002286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.136.69.199",nocase; classtype:trojan-activity; sid:100002287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.143.53.34",nocase; classtype:trojan-activity; sid:100002288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.154.17.170",nocase; classtype:trojan-activity; sid:100002289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.200.16.22",nocase; classtype:trojan-activity; sid:100002290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.224.83.208",nocase; classtype:trojan-activity; sid:100002291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.53.120.109",nocase; classtype:trojan-activity; sid:100002292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.85.0.3",nocase; classtype:trojan-activity; sid:100002293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.132.129.250",nocase; classtype:trojan-activity; sid:100002294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.154.20.231",nocase; classtype:trojan-activity; sid:100002295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.158.19.130",nocase; classtype:trojan-activity; sid:100002296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.113.227",nocase; classtype:trojan-activity; sid:100002297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.113.52",nocase; classtype:trojan-activity; sid:100002298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.201.34",nocase; classtype:trojan-activity; sid:100002299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.60.146.134",nocase; classtype:trojan-activity; sid:100002300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.66.196.63",nocase; classtype:trojan-activity; sid:100002301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.9.120.40",nocase; classtype:trojan-activity; sid:100002302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.9.81.85",nocase; classtype:trojan-activity; sid:100002303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.239.73.246",nocase; classtype:trojan-activity; sid:100002304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.47.147.169",nocase; classtype:trojan-activity; sid:100002305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.68.140.254",nocase; classtype:trojan-activity; sid:100002306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.96.199.75",nocase; classtype:trojan-activity; sid:100002307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.0.210.218",nocase; classtype:trojan-activity; sid:100002308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.113.239.207",nocase; classtype:trojan-activity; sid:100002309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.116.72.119",nocase; classtype:trojan-activity; sid:100002310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.128.147.115",nocase; classtype:trojan-activity; sid:100002311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.178.242.44",nocase; classtype:trojan-activity; sid:100002312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.30.24.54",nocase; classtype:trojan-activity; sid:100002313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.150.245.203",nocase; classtype:trojan-activity; sid:100002314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.33.195.164",nocase; classtype:trojan-activity; sid:100002315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aatreefelling.co.za",nocase; classtype:trojan-activity; sid:100002316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abad.tv",nocase; classtype:trojan-activity; sid:100002317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abcd.bg",nocase; classtype:trojan-activity; sid:100002318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abissnet.net",nocase; classtype:trojan-activity; sid:100002319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aboveandbelow.com.au",nocase; classtype:trojan-activity; sid:100002320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absoftechworld.com",nocase; classtype:trojan-activity; sid:100002321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absupplies.co.uk",nocase; classtype:trojan-activity; sid:100002322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abyssos.eu",nocase; classtype:trojan-activity; sid:100002323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"academyshademani.com",nocase; classtype:trojan-activity; sid:100002324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acbick.com",nocase; classtype:trojan-activity; sid:100002325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"accesslinksgroup.com",nocase; classtype:trojan-activity; sid:100002326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aceeprc.com.aceeprc.com",nocase; classtype:trojan-activity; sid:100002327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acellr.co.uk",nocase; classtype:trojan-activity; sid:100002328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acteon.com.ar",nocase; classtype:trojan-activity; sid:100002329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"activecost.com.au",nocase; classtype:trojan-activity; sid:100002330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"addahealingmusic.com",nocase; classtype:trojan-activity; sid:100002331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.com",nocase; classtype:trojan-activity; sid:100002332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.memengers.com",nocase; classtype:trojan-activity; sid:100002333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.erapor.smk-alasror.net",nocase; classtype:trojan-activity; sid:100002334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.gentbcn.org",nocase; classtype:trojan-activity; sid:100002335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.grandoceanvilla.com",nocase; classtype:trojan-activity; sid:100002336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admission.kmctartskuttippuram.org",nocase; classtype:trojan-activity; sid:100002337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adventureexplorer.in",nocase; classtype:trojan-activity; sid:100002338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aeropilates.cl",nocase; classtype:trojan-activity; sid:100002339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afnan-amc.com",nocase; classtype:trojan-activity; sid:100002340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afoninblog.com",nocase; classtype:trojan-activity; sid:100002341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afrimedspecialist.com",nocase; classtype:trojan-activity; sid:100002342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agemn.co.za",nocase; classtype:trojan-activity; sid:100002343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenciadigitalwdys.com",nocase; classtype:trojan-activity; sid:100002344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenda.gmelloinformatica.com.br",nocase; classtype:trojan-activity; sid:100002345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agentt.ac.ug",nocase; classtype:trojan-activity; sid:100002346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agile8studio.com",nocase; classtype:trojan-activity; sid:100002347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aiecons.com",nocase; classtype:trojan-activity; sid:100002348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aimnaukri.com",nocase; classtype:trojan-activity; sid:100002349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aiqtest.com",nocase; classtype:trojan-activity; sid:100002350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aitorocio.com",nocase; classtype:trojan-activity; sid:100002351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajpharmaholding.com",nocase; classtype:trojan-activity; sid:100002352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajstudiollc.com",nocase; classtype:trojan-activity; sid:100002353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"akdvidyalaya.com",nocase; classtype:trojan-activity; sid:100002354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"al-wahd.com",nocase; classtype:trojan-activity; sid:100002355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alasdemariposas.org",nocase; classtype:trojan-activity; sid:100002356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alberts.diamondrelationscrm.us",nocase; classtype:trojan-activity; sid:100002357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alemelektronik.com",nocase; classtype:trojan-activity; sid:100002358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alena1971.es",nocase; classtype:trojan-activity; sid:100002359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alexdubai.com.aldiabsteel.com",nocase; classtype:trojan-activity; sid:100002360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alka.institute",nocase; classtype:trojan-activity; sid:100002361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"allforcreative.com.au",nocase; classtype:trojan-activity; sid:100002362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alltheway.travel",nocase; classtype:trojan-activity; sid:100002363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alpaylar.com.tr",nocase; classtype:trojan-activity; sid:100002364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"am-concepts.ca",nocase; classtype:trojan-activity; sid:100002365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amamontajes.com",nocase; classtype:trojan-activity; sid:100002366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarresdeamorymaestroshechiceros.com",nocase; classtype:trojan-activity; sid:100002367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarteargentina.com.ar",nocase; classtype:trojan-activity; sid:100002368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amos524.org",nocase; classtype:trojan-activity; sid:100002369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ams.alvinasschools.org.ng",nocase; classtype:trojan-activity; sid:100002370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anadelgbt.org",nocase; classtype:trojan-activity; sid:100002371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anantam.net.in",nocase; classtype:trojan-activity; sid:100002372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreelapeyre.com",nocase; classtype:trojan-activity; sid:100002373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andremaraisbeleggings.co.za",nocase; classtype:trojan-activity; sid:100002374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ac.ug",nocase; classtype:trojan-activity; sid:100002375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ug",nocase; classtype:trojan-activity; sid:100002376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreshconcejal.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelazgheibld.com",nocase; classtype:trojan-activity; sid:100002378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelsdetour.com",nocase; classtype:trojan-activity; sid:100002379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angloteste.bigprime.com.br",nocase; classtype:trojan-activity; sid:100002380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anhung1102.vn",nocase; classtype:trojan-activity; sid:100002381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anurontv.com",nocase; classtype:trojan-activity; sid:100002382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anysbergbiltong.co.za",nocase; classtype:trojan-activity; sid:100002383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apartamentoscitta.com",nocase; classtype:trojan-activity; sid:100002384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api-ms.cobainaja.id",nocase; classtype:trojan-activity; sid:100002385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.cstdevs.com",nocase; classtype:trojan-activity; sid:100002386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.quocbao.biz",nocase; classtype:trojan-activity; sid:100002387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apoolcondo.com",nocase; classtype:trojan-activity; sid:100002388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.adsensearticle.com",nocase; classtype:trojan-activity; sid:100002389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.explicitsurveys.co.uk",nocase; classtype:trojan-activity; sid:100002390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.prerana.info",nocase; classtype:trojan-activity; sid:100002391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apps.saintsoporte.com",nocase; classtype:trojan-activity; sid:100002392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aps-scribe.com",nocase; classtype:trojan-activity; sid:100002393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aps-sv.com",nocase; classtype:trojan-activity; sid:100002394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apsusa.aero",nocase; classtype:trojan-activity; sid:100002395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"areyoulivingwell.com",nocase; classtype:trojan-activity; sid:100002396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"artedibujoyarquitectura.com",nocase; classtype:trojan-activity; sid:100002397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"arwenyapi.com",nocase; classtype:trojan-activity; sid:100002398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ask-regard.call-save.biz",nocase; classtype:trojan-activity; sid:100002399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atfile.com",nocase; classtype:trojan-activity; sid:100002400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"athenacapsg.com",nocase; classtype:trojan-activity; sid:100002401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atlanticsteelprocessing.com",nocase; classtype:trojan-activity; sid:100002402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atlasconcreteworks.com",nocase; classtype:trojan-activity; sid:100002403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"attach.66rpg.com",nocase; classtype:trojan-activity; sid:100002404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atteuqpotentialunlimited.com",nocase; classtype:trojan-activity; sid:100002405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"augustair.com",nocase; classtype:trojan-activity; sid:100002406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"avadhanagames.com",nocase; classtype:trojan-activity; sid:100002407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ayahuascasp.com.br",nocase; classtype:trojan-activity; sid:100002408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ayamallah.com",nocase; classtype:trojan-activity; sid:100002409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azmeasurement.com",nocase; classtype:trojan-activity; sid:100002410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"b2b.toptanakaryakit.com.tr",nocase; classtype:trojan-activity; sid:100002411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"backgrounds.pk",nocase; classtype:trojan-activity; sid:100002412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"badeggdesign.com",nocase; classtype:trojan-activity; sid:100002413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"balealgodon.mx",nocase; classtype:trojan-activity; sid:100002414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ballina.andrewmaughan.com",nocase; classtype:trojan-activity; sid:100002415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bangkok-orchids.com",nocase; classtype:trojan-activity; sid:100002416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bangladeshunbound.com",nocase; classtype:trojan-activity; sid:100002417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bary.sz4h.com",nocase; classtype:trojan-activity; sid:100002418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bash.givemexyz.in",nocase; classtype:trojan-activity; sid:100002419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk",nocase; classtype:trojan-activity; sid:100002420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bavhome.com",nocase; classtype:trojan-activity; sid:100002421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bbia.co.uk",nocase; classtype:trojan-activity; sid:100002422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcmt.elin.co.za",nocase; classtype:trojan-activity; sid:100002423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcrg.co.za",nocase; classtype:trojan-activity; sid:100002424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bdnextrend.xyz",nocase; classtype:trojan-activity; sid:100002425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bearcatpumps.com.cn",nocase; classtype:trojan-activity; sid:100002426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beautincollagen.rs",nocase; classtype:trojan-activity; sid:100002427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bekape.co.id",nocase; classtype:trojan-activity; sid:100002428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beor360.com",nocase; classtype:trojan-activity; sid:100002429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bespokeweddings.ie",nocase; classtype:trojan-activity; sid:100002430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bestcarenepal.com",nocase; classtype:trojan-activity; sid:100002431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betone.co.kr",nocase; classtype:trojan-activity; sid:100002432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beveragesmiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bhavaniengineering.com",nocase; classtype:trojan-activity; sid:100002434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bigmikesupplies.co.za",nocase; classtype:trojan-activity; sid:100002435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilbosaquet.ug",nocase; classtype:trojan-activity; sid:100002436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilhen.co.za",nocase; classtype:trojan-activity; sid:100002437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"billing.citywine.in",nocase; classtype:trojan-activity; sid:100002438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"billing.rahitechnosoft.com",nocase; classtype:trojan-activity; sid:100002439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"binoy.stalphonsamissionva.org",nocase; classtype:trojan-activity; sid:100002440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"biometrico.gpotecnosystems.com",nocase; classtype:trojan-activity; sid:100002441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bioskey.com",nocase; classtype:trojan-activity; sid:100002442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birdi.elin.co.za",nocase; classtype:trojan-activity; sid:100002443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birminghamlink.org",nocase; classtype:trojan-activity; sid:100002444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bizztradingbot.nl",nocase; classtype:trojan-activity; sid:100002445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bl4n3.zadns.co.za",nocase; classtype:trojan-activity; sid:100002446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.callensaxen.com",nocase; classtype:trojan-activity; sid:100002447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.cast.re",nocase; classtype:trojan-activity; sid:100002448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.difusodesign.com",nocase; classtype:trojan-activity; sid:100002449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.oyinblogs.com",nocase; classtype:trojan-activity; sid:100002450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.takbelit.com",nocase; classtype:trojan-activity; sid:100002451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bmlifestyle.co.uk",nocase; classtype:trojan-activity; sid:100002452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bnrnews.id",nocase; classtype:trojan-activity; sid:100002453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"boatpecas.com.br",nocase; classtype:trojan-activity; sid:100002454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bodenstein.co.za",nocase; classtype:trojan-activity; sid:100002455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"booksearch.com",nocase; classtype:trojan-activity; sid:100002456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bophelocare.co.za",nocase; classtype:trojan-activity; sid:100002457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bounces.mi-fs.com",nocase; classtype:trojan-activity; sid:100002458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"boutiqueofferte.com",nocase; classtype:trojan-activity; sid:100002459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bpo.correct.go.th",nocase; classtype:trojan-activity; sid:100002460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brandtrust.com.pk",nocase; classtype:trojan-activity; sid:100002461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"braunfinancial.com.au",nocase; classtype:trojan-activity; sid:100002462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brendanquine.com",nocase; classtype:trojan-activity; sid:100002463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brideofmessiah.com",nocase; classtype:trojan-activity; sid:100002464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightaffiliatesales.org",nocase; classtype:trojan-activity; sid:100002465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightmega.com",nocase; classtype:trojan-activity; sid:100002466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightstarshop.com",nocase; classtype:trojan-activity; sid:100002467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"browardinsurancemiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bt2.elin.co.za",nocase; classtype:trojan-activity; sid:100002469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"btdapi.robotake.com",nocase; classtype:trojan-activity; sid:100002470; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buigiaphat.com.vn",nocase; classtype:trojan-activity; sid:100002471; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bulkyfoodja.com",nocase; classtype:trojan-activity; sid:100002472; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bullseyemedia.in",nocase; classtype:trojan-activity; sid:100002473; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"busandvanrentalmalaysia.com",nocase; classtype:trojan-activity; sid:100002474; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buscascolegios.diit.cl",nocase; classtype:trojan-activity; sid:100002475; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"business.softberg.ro",nocase; classtype:trojan-activity; sid:100002476; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"business2.softberg.ro",nocase; classtype:trojan-activity; sid:100002477; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bydspa.cl",nocase; classtype:trojan-activity; sid:100002478; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c.oooooooooo.ga",nocase; classtype:trojan-activity; sid:100002479; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c0140529.ferozo.com",nocase; classtype:trojan-activity; sid:100002480; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"caballo.com.au",nocase; classtype:trojan-activity; sid:100002481; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cacaoprojects.com",nocase; classtype:trojan-activity; sid:100002482; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"calgaryautorepairservice.com",nocase; classtype:trojan-activity; sid:100002483; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"callbury.in",nocase; classtype:trojan-activity; sid:100002484; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"camminachetipassa.it",nocase; classtype:trojan-activity; sid:100002485; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"canadianwork.cc",nocase; classtype:trojan-activity; sid:100002486; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capitalgroup-kw.com",nocase; classtype:trojan-activity; sid:100002487; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capoeiraventrelivre.com",nocase; classtype:trojan-activity; sid:100002488; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cardilicores.com",nocase; classtype:trojan-activity; sid:100002489; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cashyinvestment.org",nocase; classtype:trojan-activity; sid:100002490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"catchperch.com",nocase; classtype:trojan-activity; sid:100002491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"catchpoolshetlands.co.uk",nocase; classtype:trojan-activity; sid:100002492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cazyacustomfurniture.com",nocase; classtype:trojan-activity; sid:100002493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cbn.hypervoizd.com",nocase; classtype:trojan-activity; sid:100002494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ccauthority.net",nocase; classtype:trojan-activity; sid:100002495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdaonline.com.ar",nocase; classtype:trojan-activity; sid:100002496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cec.asso.ac-amiens.fr",nocase; classtype:trojan-activity; sid:100002497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cecra.cl",nocase; classtype:trojan-activity; sid:100002498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cellas.sk",nocase; classtype:trojan-activity; sid:100002499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cendekiabinaaksara.com",nocase; classtype:trojan-activity; sid:100002500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cfs5.tistory.com",nocase; classtype:trojan-activity; sid:100002501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ch.rmu.ac.th",nocase; classtype:trojan-activity; sid:100002502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chance5.xyz",nocase; classtype:trojan-activity; sid:100002503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"changematterscounselling.com",nocase; classtype:trojan-activity; sid:100002504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chardhamdodham.com",nocase; classtype:trojan-activity; sid:100002505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"check.askwordpressguru.com",nocase; classtype:trojan-activity; sid:100002506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chezalice.co.za",nocase; classtype:trojan-activity; sid:100002507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"childselect.com",nocase; classtype:trojan-activity; sid:100002508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile.myvnc.com",nocase; classtype:trojan-activity; sid:100002509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile80.myvnc.com",nocase; classtype:trojan-activity; sid:100002510; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cible-energy.com",nocase; classtype:trojan-activity; sid:100002511; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cifeer.net",nocase; classtype:trojan-activity; sid:100002512; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cirugiadenarizbucaramanga.com",nocase; classtype:trojan-activity; sid:100002513; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citihits.lk",nocase; classtype:trojan-activity; sid:100002514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citssolutions.co.za",nocase; classtype:trojan-activity; sid:100002515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citycapproperty.ru",nocase; classtype:trojan-activity; sid:100002516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cityglobalgospel.com",nocase; classtype:trojan-activity; sid:100002517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"civi.istmejia.com",nocase; classtype:trojan-activity; sid:100002518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cleanbydesignllc.com",nocase; classtype:trojan-activity; sid:100002519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloud.fc.co.mz",nocase; classtype:trojan-activity; sid:100002520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cm-arquitetos.com",nocase; classtype:trojan-activity; sid:100002521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codsambal.com",nocase; classtype:trojan-activity; sid:100002522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colempaques.info",nocase; classtype:trojan-activity; sid:100002523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colinde.pricesne.com",nocase; classtype:trojan-activity; sid:100002524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colorpak.pl",nocase; classtype:trojan-activity; sid:100002525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"community.reimclub.com",nocase; classtype:trojan-activity; sid:100002526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"comosairdoburaco.com.br",nocase; classtype:trojan-activity; sid:100002527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"competancy.indigoconsult.net",nocase; classtype:trojan-activity; sid:100002528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"conceptimagine.ro",nocase; classtype:trojan-activity; sid:100002529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"config.cqhbkjzx.com",nocase; classtype:trojan-activity; sid:100002530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"connectcapital.com.br",nocase; classtype:trojan-activity; sid:100002531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"constructoralyon.com",nocase; classtype:trojan-activity; sid:100002532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"consulateins.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"contributeindustry.com",nocase; classtype:trojan-activity; sid:100002534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"controleautomacao.com.br",nocase; classtype:trojan-activity; sid:100002535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"copelandscapes.com",nocase; classtype:trojan-activity; sid:100002536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"coulsongraphics.com",nocase; classtype:trojan-activity; sid:100002537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"count.mail.163.com.impactmedfoundation.com",nocase; classtype:trojan-activity; sid:100002538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"covid19.cyberschool.or.id",nocase; classtype:trojan-activity; sid:100002539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cpanel.shivay.net",nocase; classtype:trojan-activity; sid:100002540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cr-sq.com",nocase; classtype:trojan-activity; sid:100002541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"craftech.nxtnet.ga",nocase; classtype:trojan-activity; sid:100002542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crearechile.cl",nocase; classtype:trojan-activity; sid:100002543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"creationskateboards.com",nocase; classtype:trojan-activity; sid:100002544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crecerco.com",nocase; classtype:trojan-activity; sid:100002545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crittersbythebay.com",nocase; classtype:trojan-activity; sid:100002546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crm.notariavieitoyvelamazan.com",nocase; classtype:trojan-activity; sid:100002547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crmfarko.manivelasst.com",nocase; classtype:trojan-activity; sid:100002548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crmroche.manivelasst.com",nocase; classtype:trojan-activity; sid:100002549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crscorretordeimoveis.com.br",nocase; classtype:trojan-activity; sid:100002550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cse-engineer.com",nocase; classtype:trojan-activity; sid:100002551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"csnserver.com",nocase; classtype:trojan-activity; sid:100002552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ctracknxt.in",nocase; classtype:trojan-activity; sid:100002553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cubescargoexpress.com",nocase; classtype:trojan-activity; sid:100002554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"curasoles.co.za",nocase; classtype:trojan-activity; sid:100002555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"currantmedia.com",nocase; classtype:trojan-activity; sid:100002556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cwa.mx",nocase; classtype:trojan-activity; sid:100002557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cyclomove.com",nocase; classtype:trojan-activity; sid:100002558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cynkon.kairoscs.net",nocase; classtype:trojan-activity; sid:100002559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"czsl.91756.cn",nocase; classtype:trojan-activity; sid:100002560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d.powerofwish.com",nocase; classtype:trojan-activity; sid:100002561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d9.99ddd.com",nocase; classtype:trojan-activity; sid:100002562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"da.alibuf.com",nocase; classtype:trojan-activity; sid:100002563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dagiionline.com",nocase; classtype:trojan-activity; sid:100002564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"damagedessentialtelecommunications.testmail4.repl.co",nocase; classtype:trojan-activity; sid:100002565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"danaevara.com",nocase; classtype:trojan-activity; sid:100002566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dartoonpictures.com",nocase; classtype:trojan-activity; sid:100002567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.cdevelop.org",nocase; classtype:trojan-activity; sid:100002568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.over-blog-kiwi.com",nocase; classtype:trojan-activity; sid:100002569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datapolish.com",nocase; classtype:trojan-activity; sid:100002570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dating.khokhas.co.za",nocase; classtype:trojan-activity; sid:100002571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datsom.vn",nocase; classtype:trojan-activity; sid:100002572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davethompson.me.uk",nocase; classtype:trojan-activity; sid:100002573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davidmcguinness.info",nocase; classtype:trojan-activity; sid:100002574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dayspringdaisies.com",nocase; classtype:trojan-activity; sid:100002575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dd.qiyuea.cn",nocase; classtype:trojan-activity; sid:100002576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"de.gsearch.com.de",nocase; classtype:trojan-activity; sid:100002577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"decifrar.com.br",nocase; classtype:trojan-activity; sid:100002578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deigratia2.elin.co.za",nocase; classtype:trojan-activity; sid:100002579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dekovizyon.com",nocase; classtype:trojan-activity; sid:100002580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo-cliente.mindcreative.com.br",nocase; classtype:trojan-activity; sid:100002581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo.glassforcars.com.au",nocase; classtype:trojan-activity; sid:100002582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo.iiitindia.in",nocase; classtype:trojan-activity; sid:100002583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo6.hiites.com",nocase; classtype:trojan-activity; sid:100002584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dent-estet.com",nocase; classtype:trojan-activity; sid:100002585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dental.xiaoxiao.media",nocase; classtype:trojan-activity; sid:100002586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dentalalliance.se",nocase; classtype:trojan-activity; sid:100002587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"desertlandtrd.com",nocase; classtype:trojan-activity; sid:100002588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"designerliving.co.za",nocase; classtype:trojan-activity; sid:100002589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"desiringhands.com",nocase; classtype:trojan-activity; sid:100002590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"despertaresi.com.br",nocase; classtype:trojan-activity; sid:100002591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"destinymc.co.za",nocase; classtype:trojan-activity; sid:100002592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"detorre.es",nocase; classtype:trojan-activity; sid:100002593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev.sebpo.net",nocase; classtype:trojan-activity; sid:100002594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev.watch-store.eu",nocase; classtype:trojan-activity; sid:100002595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dezcom.com",nocase; classtype:trojan-activity; sid:100002596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dfcf.91756.cn",nocase; classtype:trojan-activity; sid:100002597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dfsfcsfcdsfsdvcfsvcscv.com",nocase; classtype:trojan-activity; sid:100002598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"diamantenegro.mi-fs.com",nocase; classtype:trojan-activity; sid:100002599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dienmayminhhung.com",nocase; classtype:trojan-activity; sid:100002600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digilib.dianhusada.ac.id",nocase; classtype:trojan-activity; sid:100002601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digisails.org",nocase; classtype:trojan-activity; sid:100002602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"disinfection-cleaning.co.za",nocase; classtype:trojan-activity; sid:100002603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"djking.f3322.net",nocase; classtype:trojan-activity; sid:100002604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.1003b.56a.com",nocase; classtype:trojan-activity; sid:100002605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.198424.com",nocase; classtype:trojan-activity; sid:100002606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.installcdn-aws.com",nocase; classtype:trojan-activity; sid:100002607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.packetstormsecurity.net",nocase; classtype:trojan-activity; sid:100002608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.rina-roleplay.com",nocase; classtype:trojan-activity; sid:100002609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dnn.alibuf.com",nocase; classtype:trojan-activity; sid:100002610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dns.cyberium.cc",nocase; classtype:trojan-activity; sid:100002611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dockerupdate.anondns.net",nocase; classtype:trojan-activity; sid:100002612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docman.orientalservices.in",nocase; classtype:trojan-activity; sid:100002613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dodsonimaging.com",nocase; classtype:trojan-activity; sid:100002614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"doitunlimited.com",nocase; classtype:trojan-activity; sid:100002615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dokan.blueberrytec.com",nocase; classtype:trojan-activity; sid:100002616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom-chel74.ru",nocase; classtype:trojan-activity; sid:100002617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom.daf.free.fr",nocase; classtype:trojan-activity; sid:100002618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"doncedyhall.com",nocase; classtype:trojan-activity; sid:100002619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"donghobinhminh.com",nocase; classtype:trojan-activity; sid:100002620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dongphuctop.com",nocase; classtype:trojan-activity; sid:100002621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"donwnloasecury.ath.cx",nocase; classtype:trojan-activity; sid:100002622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosame.com",nocase; classtype:trojan-activity; sid:100002623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosman.pl",nocase; classtype:trojan-activity; sid:100002624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dovberger.com",nocase; classtype:trojan-activity; sid:100002625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.pcclear.com",nocase; classtype:trojan-activity; sid:100002626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.udashi.com",nocase; classtype:trojan-activity; sid:100002627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.webbora.com",nocase; classtype:trojan-activity; sid:100002628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down1.arpun.com",nocase; classtype:trojan-activity; sid:100002629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.caihong.com",nocase; classtype:trojan-activity; sid:100002630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.doumaibiji.cn",nocase; classtype:trojan-activity; sid:100002631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.exrnybuf.cn",nocase; classtype:trojan-activity; sid:100002632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.kaobeitu.com",nocase; classtype:trojan-activity; sid:100002633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.pdf00.cn",nocase; classtype:trojan-activity; sid:100002634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.rising.com.cn",nocase; classtype:trojan-activity; sid:100002635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.skycn.com",nocase; classtype:trojan-activity; sid:100002636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.zjsyawqj.cn",nocase; classtype:trojan-activity; sid:100002637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dragonsknot.com",nocase; classtype:trojan-activity; sid:100002638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drbaby.com.sa",nocase; classtype:trojan-activity; sid:100002639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dream.pics",nocase; classtype:trojan-activity; sid:100002640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drgroup.co.za",nocase; classtype:trojan-activity; sid:100002641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drools-moved.46999.n3.nabble.com",nocase; classtype:trojan-activity; sid:100002642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drsha.innovativesolutions.mobi",nocase; classtype:trojan-activity; sid:100002643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsdisplay.co.uk",nocase; classtype:trojan-activity; sid:100002644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsenterprize.co.za",nocase; classtype:trojan-activity; sid:100002645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsspainting.com",nocase; classtype:trojan-activity; sid:100002646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"du-wizards.com",nocase; classtype:trojan-activity; sid:100002647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duanhaozhang.com",nocase; classtype:trojan-activity; sid:100002648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duque.guantanameratravel.com",nocase; classtype:trojan-activity; sid:100002649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dutapp.wisolve.co.za",nocase; classtype:trojan-activity; sid:100002650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duvalcharter.dekitout.com",nocase; classtype:trojan-activity; sid:100002651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dx.qqyewu.com",nocase; classtype:trojan-activity; sid:100002652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dzinestudio87.co.uk",nocase; classtype:trojan-activity; sid:100002653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-commerce.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100002654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e.sldov.ru",nocase; classtype:trojan-activity; sid:100002655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eandgdesign.com.ng",nocase; classtype:trojan-activity; sid:100002656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eastsheen-glaziers.co.uk",nocase; classtype:trojan-activity; sid:100002657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ebruyatkin.com",nocase; classtype:trojan-activity; sid:100002658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"edu.saicraftsman.com",nocase; classtype:trojan-activity; sid:100002659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eedo.ee",nocase; classtype:trojan-activity; sid:100002660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"efficientegroup.com",nocase; classtype:trojan-activity; sid:100002661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"elbauldenora.com",nocase; classtype:trojan-activity; sid:100002662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"emaids.co.za",nocase; classtype:trojan-activity; sid:100002663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"emaz.pk",nocase; classtype:trojan-activity; sid:100002664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"emlak.ygtsoft.com",nocase; classtype:trojan-activity; sid:100002665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"en.baoend.com",nocase; classtype:trojan-activity; sid:100002666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enc-tech.com",nocase; classtype:trojan-activity; sid:100002667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"endurotanzania.co.tz",nocase; classtype:trojan-activity; sid:100002668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ennovate.elin.co.za",nocase; classtype:trojan-activity; sid:100002669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enriquecendocomconsorcio.com.br",nocase; classtype:trojan-activity; sid:100002670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"equimination.ee",nocase; classtype:trojan-activity; sid:100002671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"erp.nanotechproautocare.com",nocase; classtype:trojan-activity; sid:100002672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"erp.zilymax.com",nocase; classtype:trojan-activity; sid:100002673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"escola.probommar.org.br",nocase; classtype:trojan-activity; sid:100002674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"esnconsultants.com",nocase; classtype:trojan-activity; sid:100002675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"essentia.org.br",nocase; classtype:trojan-activity; sid:100002676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eubanks7.com",nocase; classtype:trojan-activity; sid:100002677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"europeanzonexxi.com",nocase; classtype:trojan-activity; sid:100002678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evidencemarketing.ca",nocase; classtype:trojan-activity; sid:100002679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exilum.com",nocase; classtype:trojan-activity; sid:100002680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exitoalfaomega.co",nocase; classtype:trojan-activity; sid:100002681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"extrovertoffers.com",nocase; classtype:trojan-activity; sid:100002682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"f1sol.com",nocase; classtype:trojan-activity; sid:100002683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fahrzeugdrive.com",nocase; classtype:trojan-activity; sid:100002684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"familydentist.site",nocase; classtype:trojan-activity; sid:100002685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"faveraprojects.com",nocase; classtype:trojan-activity; sid:100002686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fc.co.mz",nocase; classtype:trojan-activity; sid:100002687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"felicienne.nl",nocase; classtype:trojan-activity; sid:100002688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.martellexpress.us",nocase; classtype:trojan-activity; sid:100002689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"filmotainment.com",nocase; classtype:trojan-activity; sid:100002690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"final.makkahkmcc.com",nocase; classtype:trojan-activity; sid:100002691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fineartgallerym.com",nocase; classtype:trojan-activity; sid:100002692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fisconline.casa",nocase; classtype:trojan-activity; sid:100002693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fix-america-now.org",nocase; classtype:trojan-activity; sid:100002694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fixauto.illumetechnology.com",nocase; classtype:trojan-activity; sid:100002695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fixturegovernment.com",nocase; classtype:trojan-activity; sid:100002696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fkd.derpcity.ru",nocase; classtype:trojan-activity; sid:100002697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flexypay.dsquaregroup.com",nocase; classtype:trojan-activity; sid:100002698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flintspin.com",nocase; classtype:trojan-activity; sid:100002699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flyingbuddhadesign.com",nocase; classtype:trojan-activity; sid:100002700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fmjplastering.co.uk",nocase; classtype:trojan-activity; sid:100002701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fms.buladde.or.ug",nocase; classtype:trojan-activity; sid:100002702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"follower.instantcashback.in",nocase; classtype:trojan-activity; sid:100002703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foothills.com.br",nocase; classtype:trojan-activity; sid:100002704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"footweardirect.elin.co.za",nocase; classtype:trojan-activity; sid:100002705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"forum.mdb.nu",nocase; classtype:trojan-activity; sid:100002706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fotoobjetivo.com",nocase; classtype:trojan-activity; sid:100002707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foundationrepairhoustontx.net",nocase; classtype:trojan-activity; sid:100002708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foxeps.com.br",nocase; classtype:trojan-activity; sid:100002709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fraud.bpcbankingtech.com",nocase; classtype:trojan-activity; sid:100002710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freecnetdownload.com",nocase; classtype:trojan-activity; sid:100002711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freisites.com.br",nocase; classtype:trojan-activity; sid:100002712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ftp.n3twork30cm.ml",nocase; classtype:trojan-activity; sid:100002713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fullelectronica.com.ar",nocase; classtype:trojan-activity; sid:100002714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"funletters.net",nocase; classtype:trojan-activity; sid:100002715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fusionfiresolutions.com",nocase; classtype:trojan-activity; sid:100002716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"futbolpr.com",nocase; classtype:trojan-activity; sid:100002717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"futuregraphics.com.ar",nocase; classtype:trojan-activity; sid:100002718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"g.pinmonkey.xyz",nocase; classtype:trojan-activity; sid:100002719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gametwogame.com",nocase; classtype:trojan-activity; sid:100002720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garciadogshow.com",nocase; classtype:trojan-activity; sid:100002721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow.myvnc.com",nocase; classtype:trojan-activity; sid:100002722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow4.myvnc.com",nocase; classtype:trojan-activity; sid:100002723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gastoudergonny.nl",nocase; classtype:trojan-activity; sid:100002724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gbbulls.co.uk",nocase; classtype:trojan-activity; sid:100002725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gcpc.co.id.chronoscurtain.com",nocase; classtype:trojan-activity; sid:100002726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"generaldeviales.com",nocase; classtype:trojan-activity; sid:100002727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfmodd1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100002728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfold1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100002729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghettohub.co.za",nocase; classtype:trojan-activity; sid:100002730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghislain.dartois.pagesperso-orange.fr",nocase; classtype:trojan-activity; sid:100002731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giadungg7.com",nocase; classtype:trojan-activity; sid:100002732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giddos.ga",nocase; classtype:trojan-activity; sid:100002733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"glowinmedia.co.ke",nocase; classtype:trojan-activity; sid:100002734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmsebpl.com",nocase; classtype:trojan-activity; sid:100002735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmtransformationacademy.com",nocase; classtype:trojan-activity; sid:100002736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmvadmission.org",nocase; classtype:trojan-activity; sid:100002737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnimelf.net",nocase; classtype:trojan-activity; sid:100002738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnscrew.ro",nocase; classtype:trojan-activity; sid:100002739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gold.investforex.id",nocase; classtype:trojan-activity; sid:100002740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcake.co.id",nocase; classtype:trojan-activity; sid:100002741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com",nocase; classtype:trojan-activity; sid:100002742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com.au",nocase; classtype:trojan-activity; sid:100002743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"golden-memories-funerals.yourpageserver.com",nocase; classtype:trojan-activity; sid:100002744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldenasiacapital.com",nocase; classtype:trojan-activity; sid:100002745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gorecycle.fahadjutt.com",nocase; classtype:trojan-activity; sid:100002746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gpotecnosystems.com",nocase; classtype:trojan-activity; sid:100002747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gracejukes.com",nocase; classtype:trojan-activity; sid:100002748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"grovershospital.com",nocase; classtype:trojan-activity; sid:100002749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"grupoinmare.com",nocase; classtype:trojan-activity; sid:100002750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gruposelt.000webhostapp.com",nocase; classtype:trojan-activity; sid:100002751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gruppodomus.com.br",nocase; classtype:trojan-activity; sid:100002752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gs.monerorx.com",nocase; classtype:trojan-activity; sid:100002753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"guide-to-cell-phones.com",nocase; classtype:trojan-activity; sid:100002754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gulfac-house.com",nocase; classtype:trojan-activity; sid:100002755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gvpcdpgc.edu.in",nocase; classtype:trojan-activity; sid:100002756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"habbotips.free.fr",nocase; classtype:trojan-activity; sid:100002757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hagebakken.no",nocase; classtype:trojan-activity; sid:100002758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hamptonpartyoffive.com",nocase; classtype:trojan-activity; sid:100002759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hashmati.com",nocase; classtype:trojan-activity; sid:100002760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hassanproduct.com",nocase; classtype:trojan-activity; sid:100002761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hchfug.org",nocase; classtype:trojan-activity; sid:100002762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hd11315.com",nocase; classtype:trojan-activity; sid:100002763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hdkamera2003.hu",nocase; classtype:trojan-activity; sid:100002764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hds.sz4h.com",nocase; classtype:trojan-activity; sid:100002765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"heavymaq.cl",nocase; classtype:trojan-activity; sid:100002766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hellogorgeous.com.au",nocase; classtype:trojan-activity; sid:100002767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"help.hizuko.com",nocase; classtype:trojan-activity; sid:100002768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"herchinfitout.com.sg",nocase; classtype:trojan-activity; sid:100002769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hhaward.org",nocase; classtype:trojan-activity; sid:100002770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandroadcoc.com",nocase; classtype:trojan-activity; sid:100002771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandslasvegas.atakdev.com",nocase; classtype:trojan-activity; sid:100002772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hindi.factsriver.com",nocase; classtype:trojan-activity; sid:100002773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hiptool.net",nocase; classtype:trojan-activity; sid:100002774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitpe.com",nocase; classtype:trojan-activity; sid:100002775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitstation.nl",nocase; classtype:trojan-activity; sid:100002776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hmpmall.co.kr",nocase; classtype:trojan-activity; sid:100002777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoagietesting10.com",nocase; classtype:trojan-activity; sid:100002778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoayeuthuong-my.sharepoint.com",nocase; classtype:trojan-activity; sid:100002779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"holmesservices.mobiledevsite.co",nocase; classtype:trojan-activity; sid:100002780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"homefindersolutions.com",nocase; classtype:trojan-activity; sid:100002781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hongluosi.com",nocase; classtype:trojan-activity; sid:100002782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hookedupboatclub.com",nocase; classtype:trojan-activity; sid:100002783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hortizwp.eastus.cloudapp.azure.com",nocase; classtype:trojan-activity; sid:100002784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostingparacolombia.com",nocase; classtype:trojan-activity; sid:100002785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostzaa.com",nocase; classtype:trojan-activity; sid:100002786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"houstonshutters.site",nocase; classtype:trojan-activity; sid:100002787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hr2019.vrcom7.com",nocase; classtype:trojan-activity; sid:100002788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hrnautica.com.br",nocase; classtype:trojan-activity; sid:100002789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hseda.com",nocase; classtype:trojan-activity; sid:100002790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsmwebapp.com",nocase; classtype:trojan-activity; sid:100002791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"htownbars.com",nocase; classtype:trojan-activity; sid:100002792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hubtech.co.za",nocase; classtype:trojan-activity; sid:100002793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"huellacero.cl",nocase; classtype:trojan-activity; sid:100002794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hunggiang.vn",nocase; classtype:trojan-activity; sid:100002795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"husamiyahschool.com",nocase; classtype:trojan-activity; sid:100002796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iabmixx2020.rayadigital.online",nocase; classtype:trojan-activity; sid:100002797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iam313.com",nocase; classtype:trojan-activity; sid:100002798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iammdshanto.com",nocase; classtype:trojan-activity; sid:100002799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"icon.shatangmu.cn",nocase; classtype:trojan-activity; sid:100002800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idilsoft.com",nocase; classtype:trojan-activity; sid:100002801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idj.no",nocase; classtype:trojan-activity; sid:100002802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idvindia.com",nocase; classtype:trojan-activity; sid:100002803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ieclb.com.br",nocase; classtype:trojan-activity; sid:100002804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ikexpert.com",nocase; classtype:trojan-activity; sid:100002805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ilrafrica.com",nocase; classtype:trojan-activity; sid:100002806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"images.jermiau.com",nocase; classtype:trojan-activity; sid:100002807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"imbueautoworx.co.za",nocase; classtype:trojan-activity; sid:100002808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"in-tune2016.com",nocase; classtype:trojan-activity; sid:100002809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incrediblepixels.com",nocase; classtype:trojan-activity; sid:100002810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incredicole.com",nocase; classtype:trojan-activity; sid:100002811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indrasbikaner.com",nocase; classtype:trojan-activity; sid:100002812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infair.vn",nocase; classtype:trojan-activity; sid:100002813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infovator.com",nocase; classtype:trojan-activity; sid:100002814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"initialnetworks.com",nocase; classtype:trojan-activity; sid:100002815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inodesthetotaldesigners.com",nocase; classtype:trojan-activity; sid:100002816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inrajahmundry.co.in",nocase; classtype:trojan-activity; sid:100002817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"insignificantfinecore.testmail4.repl.co",nocase; classtype:trojan-activity; sid:100002818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"instantindialoan.com",nocase; classtype:trojan-activity; sid:100002819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"insupportofchildren.co.uk",nocase; classtype:trojan-activity; sid:100002820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intellectsmart.in",nocase; classtype:trojan-activity; sid:100002821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intersel-idf.org",nocase; classtype:trojan-activity; sid:100002822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intuitiveideas.com.my",nocase; classtype:trojan-activity; sid:100002823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inversiones.arrayanfinanciero.cl",nocase; classtype:trojan-activity; sid:100002824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"invest.xpcorporative.com.br",nocase; classtype:trojan-activity; sid:100002825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"investinae.com",nocase; classtype:trojan-activity; sid:100002826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ioabc.wif.com.br",nocase; classtype:trojan-activity; sid:100002827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ipmes.ma",nocase; classtype:trojan-activity; sid:100002828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iremart.es",nocase; classtype:trojan-activity; sid:100002829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iris101.co.uk",nocase; classtype:trojan-activity; sid:100002830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iscamenabe.com",nocase; classtype:trojan-activity; sid:100002831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isiphephelocon.co.za",nocase; classtype:trojan-activity; sid:100002832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iso-dubai.net",nocase; classtype:trojan-activity; sid:100002833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"israrulhaq.me",nocase; classtype:trojan-activity; sid:100002834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isso.ps",nocase; classtype:trojan-activity; sid:100002835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ist-security.com",nocase; classtype:trojan-activity; sid:100002836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"it123.ru",nocase; classtype:trojan-activity; sid:100002837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"italiandirezione.casa",nocase; classtype:trojan-activity; sid:100002838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itc-demo.softgig.co.ke",nocase; classtype:trojan-activity; sid:100002839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itelsys.ma",nocase; classtype:trojan-activity; sid:100002840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jacktech.jackindia.com",nocase; classtype:trojan-activity; sid:100002841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jaishritours.com",nocase; classtype:trojan-activity; sid:100002842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamiekaylive.com",nocase; classtype:trojan-activity; sid:100002843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamshed.pk",nocase; classtype:trojan-activity; sid:100002844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jansen-heesch.nl",nocase; classtype:trojan-activity; sid:100002845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jathra.co.uk",nocase; classtype:trojan-activity; sid:100002846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jay.diamondrelationscrm.us",nocase; classtype:trojan-activity; sid:100002847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jebs.net.au",nocase; classtype:trojan-activity; sid:100002848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jeffdahlke.com",nocase; classtype:trojan-activity; sid:100002849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jennwolfemtb.com",nocase; classtype:trojan-activity; sid:100002850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jhayesconsulting.com",nocase; classtype:trojan-activity; sid:100002851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jiaoyuzixun.cn",nocase; classtype:trojan-activity; sid:100002852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jing-da.com.tw",nocase; classtype:trojan-activity; sid:100002853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jnanbharati.com",nocase; classtype:trojan-activity; sid:100002854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jobs.thebeessolution.com",nocase; classtype:trojan-activity; sid:100002855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"joelbonissilver.com",nocase; classtype:trojan-activity; sid:100002856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"join.cl8movement.co.za",nocase; classtype:trojan-activity; sid:100002857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"josegene.com",nocase; classtype:trojan-activity; sid:100002858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jpwoodfordco.com",nocase; classtype:trojan-activity; sid:100002859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jumpmanualjacobhiller.com",nocase; classtype:trojan-activity; sid:100002860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jupiter.toxsl.in",nocase; classtype:trojan-activity; sid:100002861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"justinscott.com.au",nocase; classtype:trojan-activity; sid:100002862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kadigital.co.uk",nocase; classtype:trojan-activity; sid:100002863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalawatihomes.com",nocase; classtype:trojan-activity; sid:100002864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalogirosfinance.com",nocase; classtype:trojan-activity; sid:100002865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kaptaanchapal.com",nocase; classtype:trojan-activity; sid:100002866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karer.by",nocase; classtype:trojan-activity; sid:100002867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"katanvetov.co.il",nocase; classtype:trojan-activity; sid:100002868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kensingtondriving.com",nocase; classtype:trojan-activity; sid:100002869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ketofitnessexpert.com",nocase; classtype:trojan-activity; sid:100002870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kevinjewelry.com.co",nocase; classtype:trojan-activity; sid:100002871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"keywatch.yourpageserver.com",nocase; classtype:trojan-activity; sid:100002872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kingssa.co.za",nocase; classtype:trojan-activity; sid:100002873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kjcpromo.com",nocase; classtype:trojan-activity; sid:100002874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kleinendeli.co.za",nocase; classtype:trojan-activity; sid:100002875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"korrectconceptservices.com",nocase; classtype:trojan-activity; sid:100002876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"krisbadminton.com",nocase; classtype:trojan-activity; sid:100002877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ktb.sch.id",nocase; classtype:trojan-activity; sid:100002878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kubatoglubaklava.com.tr",nocase; classtype:trojan-activity; sid:100002879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kumaralok.in",nocase; classtype:trojan-activity; sid:100002880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kwanfromhongkong.com",nocase; classtype:trojan-activity; sid:100002881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kz.sldov.ru",nocase; classtype:trojan-activity; sid:100002882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lacasadelosalebrijes.com",nocase; classtype:trojan-activity; sid:100002883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ladylabonde.com",nocase; classtype:trojan-activity; sid:100002884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lameguard.ru",nocase; classtype:trojan-activity; sid:100002885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laodongnhat.vn",nocase; classtype:trojan-activity; sid:100002886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laravel.pointersoftwares.com.br",nocase; classtype:trojan-activity; sid:100002887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lasermobilesounds.co.uk",nocase; classtype:trojan-activity; sid:100002888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laura9630fr.com",nocase; classtype:trojan-activity; sid:100002889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lauratomismith.com",nocase; classtype:trojan-activity; sid:100002890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lautarosanmiguel.com",nocase; classtype:trojan-activity; sid:100002891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lawforall.edu.lk",nocase; classtype:trojan-activity; sid:100002892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lawschoolideas.xyz",nocase; classtype:trojan-activity; sid:100002893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lceventos.net",nocase; classtype:trojan-activity; sid:100002894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ld.mediaget.com",nocase; classtype:trojan-activity; sid:100002895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ldgcorp.com",nocase; classtype:trojan-activity; sid:100002896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"learning.real-academy.net",nocase; classtype:trojan-activity; sid:100002897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leasiacherise.com",nocase; classtype:trojan-activity; sid:100002898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leczkregoslup.acelero.pl",nocase; classtype:trojan-activity; sid:100002899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"legend.nu",nocase; classtype:trojan-activity; sid:100002900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leluibuffet.com.br",nocase; classtype:trojan-activity; sid:100002901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lestesteux.ca",nocase; classtype:trojan-activity; sid:100002902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"libantravel.pl",nocase; classtype:trojan-activity; sid:100002903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.arihantmbainstitute.ac.in",nocase; classtype:trojan-activity; sid:100002904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.uib.ac.id",nocase; classtype:trojan-activity; sid:100002905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lidoraggiodisole.it",nocase; classtype:trojan-activity; sid:100002906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lifebeam.elin.co.za",nocase; classtype:trojan-activity; sid:100002907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lindnerelektroanlagen.de",nocase; classtype:trojan-activity; sid:100002908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linkintec.cn",nocase; classtype:trojan-activity; sid:100002909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"liquidaz.casa",nocase; classtype:trojan-activity; sid:100002910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"livetrack.in",nocase; classtype:trojan-activity; sid:100002911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lloydsindian.co.uk",nocase; classtype:trojan-activity; sid:100002912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lm.stagingarea.co.za",nocase; classtype:trojan-activity; sid:100002913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lmaancha.co.il",nocase; classtype:trojan-activity; sid:100002914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.cstdevs.com",nocase; classtype:trojan-activity; sid:100002915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.login2.in",nocase; classtype:trojan-activity; sid:100002916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"location-voitures.ma",nocase; classtype:trojan-activity; sid:100002917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"login.trezor.com.stockfootagesindia.com",nocase; classtype:trojan-activity; sid:100002918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"logotypfabriken.se",nocase; classtype:trojan-activity; sid:100002919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotix.de",nocase; classtype:trojan-activity; sid:100002920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotusanddragonfly.com",nocase; classtype:trojan-activity; sid:100002921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.definerisco.com",nocase; classtype:trojan-activity; sid:100002922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.difusodesign.com",nocase; classtype:trojan-activity; sid:100002923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.quama.pe",nocase; classtype:trojan-activity; sid:100002924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ltc.typoten.com",nocase; classtype:trojan-activity; sid:100002925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luminouspneuma.com",nocase; classtype:trojan-activity; sid:100002926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luxomodels.com",nocase; classtype:trojan-activity; sid:100002927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m-technics.kz",nocase; classtype:trojan-activity; sid:100002928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m.estudiomoros.com.ar",nocase; classtype:trojan-activity; sid:100002929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m.mobilelocalsales.com",nocase; classtype:trojan-activity; sid:100002930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"madicon.co.za",nocase; classtype:trojan-activity; sid:100002931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"magianegramagiablancayamarres.com",nocase; classtype:trojan-activity; sid:100002932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.bs-eiendomme.co.za",nocase; classtype:trojan-activity; sid:100002933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.golimoapp.com",nocase; classtype:trojan-activity; sid:100002934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.jeffsono.org",nocase; classtype:trojan-activity; sid:100002935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maksi.feb.unib.ac.id",nocase; classtype:trojan-activity; sid:100002936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malaya.tv",nocase; classtype:trojan-activity; sid:100002937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malwarecoding.github.io",nocase; classtype:trojan-activity; sid:100002938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managed.oss-cn-beijing.aliyuncs.com",nocase; classtype:trojan-activity; sid:100002939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managemysalon.in",nocase; classtype:trojan-activity; sid:100002940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manantialesdelnorte.uy",nocase; classtype:trojan-activity; sid:100002941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mangalyaa.lk",nocase; classtype:trojan-activity; sid:100002942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manhtien.net",nocase; classtype:trojan-activity; sid:100002943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marcapinyo.ru",nocase; classtype:trojan-activity; sid:100002944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mario-sunjic.com",nocase; classtype:trojan-activity; sid:100002945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariobrown.net",nocase; classtype:trojan-activity; sid:100002946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariotessarollo.com",nocase; classtype:trojan-activity; sid:100002947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketinfosales.com",nocase; classtype:trojan-activity; sid:100002948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marksidfgs.ug",nocase; classtype:trojan-activity; sid:100002949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"masjidhabeebiyarazviya.mysunni.com",nocase; classtype:trojan-activity; sid:100002950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mastersofclientretention.com.au",nocase; classtype:trojan-activity; sid:100002951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"masterthedaybook.com",nocase; classtype:trojan-activity; sid:100002952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"materialescantu.com",nocase; classtype:trojan-activity; sid:100002953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"matruchhaya.co.in",nocase; classtype:trojan-activity; sid:100002954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maxiquim.cl",nocase; classtype:trojan-activity; sid:100002955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maxoprint.co.uk",nocase; classtype:trojan-activity; sid:100002956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maxtox.com.pk",nocase; classtype:trojan-activity; sid:100002957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maybethescobar.com",nocase; classtype:trojan-activity; sid:100002958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbgrm.com",nocase; classtype:trojan-activity; sid:100002959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbjtimes.com",nocase; classtype:trojan-activity; sid:100002960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbsolutions.ge",nocase; classtype:trojan-activity; sid:100002961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbx.com.au",nocase; classtype:trojan-activity; sid:100002962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mdasa.elin.co.za",nocase; classtype:trojan-activity; sid:100002963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medevlb.org",nocase; classtype:trojan-activity; sid:100002964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"media-server.skyinternet.com.pk",nocase; classtype:trojan-activity; sid:100002965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medianews.ge",nocase; classtype:trojan-activity; sid:100002966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mediawaysnews.com",nocase; classtype:trojan-activity; sid:100002967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medistaffconsulting.com",nocase; classtype:trojan-activity; sid:100002968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meeweb.com",nocase; classtype:trojan-activity; sid:100002969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"megagynreformas.com.br",nocase; classtype:trojan-activity; sid:100002970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"megamart.afnan-amc.com",nocase; classtype:trojan-activity; sid:100002971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mehainteriors.com",nocase; classtype:trojan-activity; sid:100002972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"melissaleiteestetica.com.br",nocase; classtype:trojan-activity; sid:100002973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mercabits.com",nocase; classtype:trojan-activity; sid:100002974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"merkathink.com",nocase; classtype:trojan-activity; sid:100002975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mertlog.com",nocase; classtype:trojan-activity; sid:100002976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"metaflip.io",nocase; classtype:trojan-activity; sid:100002977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"metalin-cr.com",nocase; classtype:trojan-activity; sid:100002978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mettaanand.org",nocase; classtype:trojan-activity; sid:100002979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meuoculosnanet.com.br",nocase; classtype:trojan-activity; sid:100002980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mfevr.com",nocase; classtype:trojan-activity; sid:100002981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot.myvnc.com",nocase; classtype:trojan-activity; sid:100002982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot80.myvnc.com",nocase; classtype:trojan-activity; sid:100002983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"micalle.com.au",nocase; classtype:trojan-activity; sid:100002984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michaelphilip.com",nocase; classtype:trojan-activity; sid:100002985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michimal2.000webhostapp.com",nocase; classtype:trojan-activity; sid:100002986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microblading.mirliandias.com.br",nocase; classtype:trojan-activity; sid:100002987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microcomm-group.com",nocase; classtype:trojan-activity; sid:100002988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mingguanwms.com",nocase; classtype:trojan-activity; sid:100002989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minuevavida.org",nocase; classtype:trojan-activity; sid:100002990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mirror.mypage.sk",nocase; classtype:trojan-activity; sid:100002991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"misterson.com",nocase; classtype:trojan-activity; sid:100002992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mixr.at",nocase; classtype:trojan-activity; sid:100002993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mkontakt.az",nocase; classtype:trojan-activity; sid:100002994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mktf.mx",nocase; classtype:trojan-activity; sid:100002995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mmdx.com",nocase; classtype:trojan-activity; sid:100002996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mmogollon.com.mx",nocase; classtype:trojan-activity; sid:100002997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mncarteam.com",nocase; classtype:trojan-activity; sid:100002998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mobile.illumetechnology.com",nocase; classtype:trojan-activity; sid:100002999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modelhouseturkey.com",nocase; classtype:trojan-activity; sid:100003000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modernmanna.org",nocase; classtype:trojan-activity; sid:100003001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"monetization.business",nocase; classtype:trojan-activity; sid:100003002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moninediy.com",nocase; classtype:trojan-activity; sid:100003003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mopai.sg",nocase; classtype:trojan-activity; sid:100003004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moreirawag.ac.ug",nocase; classtype:trojan-activity; sid:100003005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"motorcomunicacion.com",nocase; classtype:trojan-activity; sid:100003006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"msacontabil.com.br",nocase; classtype:trojan-activity; sid:100003007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mtspsmjeli.sch.id",nocase; classtype:trojan-activity; sid:100003008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mumgee.co.za",nocase; classtype:trojan-activity; sid:100003009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mundialdebienes.net",nocase; classtype:trojan-activity; sid:100003010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mundotecnologiasolar.com",nocase; classtype:trojan-activity; sid:100003011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"musaffirtours.com",nocase; classtype:trojan-activity; sid:100003012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"muzimbiti.xigubo.co.mz",nocase; classtype:trojan-activity; sid:100003013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mxpiqw.am.files.1drv.com",nocase; classtype:trojan-activity; sid:100003014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mydatebook.in",nocase; classtype:trojan-activity; sid:100003015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mymlql.com",nocase; classtype:trojan-activity; sid:100003016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myritz.vettickal.com",nocase; classtype:trojan-activity; sid:100003017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mysalons.in",nocase; classtype:trojan-activity; sid:100003018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myscape.in",nocase; classtype:trojan-activity; sid:100003019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mysura.it",nocase; classtype:trojan-activity; sid:100003020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"naeemacademy.com",nocase; classtype:trojan-activity; sid:100003021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"namnyak.co.ke",nocase; classtype:trojan-activity; sid:100003022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nap.mgsservers.com",nocase; classtype:trojan-activity; sid:100003023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"narcissisto.com",nocase; classtype:trojan-activity; sid:100003024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"narimohol.com",nocase; classtype:trojan-activity; sid:100003025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"navayurveda.in",nocase; classtype:trojan-activity; sid:100003026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nec-i.com",nocase; classtype:trojan-activity; sid:100003027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nedkellymyanmar.com",nocase; classtype:trojan-activity; sid:100003028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nelitrianggraeni.000webhostapp.com",nocase; classtype:trojan-activity; sid:100003029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nerve.untergrund.net",nocase; classtype:trojan-activity; sid:100003030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nettube.com.br",nocase; classtype:trojan-activity; sid:100003031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"networkwheels.co.za",nocase; classtype:trojan-activity; sid:100003032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neuroenergy.fahadjutt.com",nocase; classtype:trojan-activity; sid:100003033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neuromedic.com.br",nocase; classtype:trojan-activity; sid:100003034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newfuture.fr",nocase; classtype:trojan-activity; sid:100003035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newinfinitysynergy.com",nocase; classtype:trojan-activity; sid:100003036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newtreedesign.co.uk",nocase; classtype:trojan-activity; sid:100003037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newvisionopticallab.com",nocase; classtype:trojan-activity; sid:100003038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newxing.com",nocase; classtype:trojan-activity; sid:100003039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nextdigitalday.ru",nocase; classtype:trojan-activity; sid:100003040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ngdaycare.co.za",nocase; classtype:trojan-activity; sid:100003041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nguyenkekhuyen.com",nocase; classtype:trojan-activity; sid:100003042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhorangtreem.com",nocase; classtype:trojan-activity; sid:100003043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nicolas.ug",nocase; classtype:trojan-activity; sid:100003044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nidhi.iexist.in",nocase; classtype:trojan-activity; sid:100003045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nikanpolimer.ir",nocase; classtype:trojan-activity; sid:100003046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilehouse.co.ug",nocase; classtype:trojan-activity; sid:100003047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilinkeji.com",nocase; classtype:trojan-activity; sid:100003048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nimboohomes.com",nocase; classtype:trojan-activity; sid:100003049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"njtiledesigncenter.com",nocase; classtype:trojan-activity; sid:100003050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nobius.org",nocase; classtype:trojan-activity; sid:100003051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nocalnoodle.elin.co.za",nocase; classtype:trojan-activity; sid:100003052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nomadicbees.com",nocase; classtype:trojan-activity; sid:100003053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nonnarina.ax",nocase; classtype:trojan-activity; sid:100003054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"notamuzikaletleri.com",nocase; classtype:trojan-activity; sid:100003055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ns1.the-widyantos.com",nocase; classtype:trojan-activity; sid:100003056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nsb.org.uk",nocase; classtype:trojan-activity; sid:100003057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nurmarkaz.org",nocase; classtype:trojan-activity; sid:100003058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nxtnet.ga",nocase; classtype:trojan-activity; sid:100003059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nyasabigbullets.com",nocase; classtype:trojan-activity; sid:100003060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nyeh2o.com.au",nocase; classtype:trojan-activity; sid:100003061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oakleyandfriends.co.uk",nocase; classtype:trojan-activity; sid:100003062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"obseques-conseils.com",nocase; classtype:trojan-activity; sid:100003063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oecteam.com",nocase; classtype:trojan-activity; sid:100003064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohe.ie",nocase; classtype:trojan-activity; sid:100003065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohsewgorgeous.co.uk",nocase; classtype:trojan-activity; sid:100003066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oknoplastik.sk",nocase; classtype:trojan-activity; sid:100003067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oleholeh.memangbeda.website",nocase; classtype:trojan-activity; sid:100003068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaia.org",nocase; classtype:trojan-activity; sid:100003069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaromatic.com",nocase; classtype:trojan-activity; sid:100003070; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omega.az",nocase; classtype:trojan-activity; sid:100003071; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oms.pappai.com",nocase; classtype:trojan-activity; sid:100003072; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omscoc.pappai.com",nocase; classtype:trojan-activity; sid:100003073; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.listifyapp.co",nocase; classtype:trojan-activity; sid:100003074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"online.creedglobal.in",nocase; classtype:trojan-activity; sid:100003075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onlinestatis.bar",nocase; classtype:trojan-activity; sid:100003076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"open.warehousesaas.co.uk",nocase; classtype:trojan-activity; sid:100003077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"opentoronto.org",nocase; classtype:trojan-activity; sid:100003078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"opolis.io",nocase; classtype:trojan-activity; sid:100003079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"optimus.com.sg",nocase; classtype:trojan-activity; sid:100003080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"order.bizpeed.com",nocase; classtype:trojan-activity; sid:100003081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orientgatewayltd.com",nocase; classtype:trojan-activity; sid:100003082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orion445.com",nocase; classtype:trojan-activity; sid:100003083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oserve.pk",nocase; classtype:trojan-activity; sid:100003084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ot.weenets.com",nocase; classtype:trojan-activity; sid:100003085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"otolithenrichment.fahadjutt.com",nocase; classtype:trojan-activity; sid:100003086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"outletdosaquecedores.com.br",nocase; classtype:trojan-activity; sid:100003087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ozemag.com",nocase; classtype:trojan-activity; sid:100003088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p1.lingpao8.com",nocase; classtype:trojan-activity; sid:100003089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p3.zbjimg.com",nocase; classtype:trojan-activity; sid:100003090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p6.zbjimg.com",nocase; classtype:trojan-activity; sid:100003091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pablobrothel.com.ar",nocase; classtype:trojan-activity; sid:100003092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacificgroup.ws",nocase; classtype:trojan-activity; sid:100003093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacwebdesigns.com",nocase; classtype:trojan-activity; sid:100003094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pagos.krayem.com.mx",nocase; classtype:trojan-activity; sid:100003095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"palbas.cl",nocase; classtype:trojan-activity; sid:100003096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"palochusvet.szm.com",nocase; classtype:trojan-activity; sid:100003097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pamperpartypros.co.za",nocase; classtype:trojan-activity; sid:100003098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parallel.rockvideos.at",nocase; classtype:trojan-activity; sid:100003099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parejasfelices.mi-fs.com",nocase; classtype:trojan-activity; sid:100003100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parkhussion.com",nocase; classtype:trojan-activity; sid:100003101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"partharaj.me",nocase; classtype:trojan-activity; sid:100003102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"partsapp.com.br",nocase; classtype:trojan-activity; sid:100003103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastorpaulocosta.com",nocase; classtype:trojan-activity; sid:100003104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.51lg.com",nocase; classtype:trojan-activity; sid:100003105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.99ddd.com",nocase; classtype:trojan-activity; sid:100003106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch3.99ddd.com",nocase; classtype:trojan-activity; sid:100003107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paths.elin.co.za",nocase; classtype:trojan-activity; sid:100003108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patriotsupremehemp.com",nocase; classtype:trojan-activity; sid:100003109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paulmercier.biz",nocase; classtype:trojan-activity; sid:100003110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payerrealty.com",nocase; classtype:trojan-activity; sid:100003111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payments.atifsiddiqui.me",nocase; classtype:trojan-activity; sid:100003112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pcsoori.com",nocase; classtype:trojan-activity; sid:100003113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pd.oceaniarp.net",nocase; classtype:trojan-activity; sid:100003114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pemdodo.com",nocase; classtype:trojan-activity; sid:100003115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perfumeriamontes.es",nocase; classtype:trojan-activity; sid:100003116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpus.onlineman7-jombang.sch.id",nocase; classtype:trojan-activity; sid:100003117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpustekim.untirta.ac.id",nocase; classtype:trojan-activity; sid:100003118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pestoclean.co.uk",nocase; classtype:trojan-activity; sid:100003119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"petercollie.com",nocase; classtype:trojan-activity; sid:100003120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"petroindia.co.in",nocase; classtype:trojan-activity; sid:100003121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ph4s.ru",nocase; classtype:trojan-activity; sid:100003122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phasdesign.com",nocase; classtype:trojan-activity; sid:100003123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phenhuong.sanpham.online",nocase; classtype:trojan-activity; sid:100003124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phittc.com",nocase; classtype:trojan-activity; sid:100003125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"photo360.kubooking.com",nocase; classtype:trojan-activity; sid:100003126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pink99.com",nocase; classtype:trojan-activity; sid:100003127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pinkpaprika.co.uk",nocase; classtype:trojan-activity; sid:100003128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"plasfan.ind.br",nocase; classtype:trojan-activity; sid:100003129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"platinumherbal.com",nocase; classtype:trojan-activity; sid:100003130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"playground2.grupoaliadasca.com",nocase; classtype:trojan-activity; sid:100003131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pmglance.startwriteup.com",nocase; classtype:trojan-activity; sid:100003132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pointactionsg.com",nocase; classtype:trojan-activity; sid:100003133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pokojewewladyslawowie.pl",nocase; classtype:trojan-activity; sid:100003134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pole.com.vc",nocase; classtype:trojan-activity; sid:100003135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pool.phxdir.com",nocase; classtype:trojan-activity; sid:100003136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pooltablemoversdenver.net",nocase; classtype:trojan-activity; sid:100003137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"portal.premiumpunch.com",nocase; classtype:trojan-activity; sid:100003138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"posmicrosystems.com",nocase; classtype:trojan-activity; sid:100003139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"poulman.panagiotopoulos-tours.gr",nocase; classtype:trojan-activity; sid:100003140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ppdb.smk-ciptaskill.sch.id",nocase; classtype:trojan-activity; sid:100003141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestasicash.com.ar",nocase; classtype:trojan-activity; sid:100003142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestigehomeautomation.net",nocase; classtype:trojan-activity; sid:100003143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"preview2.behalen.com",nocase; classtype:trojan-activity; sid:100003144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prishaartcreations.com",nocase; classtype:trojan-activity; sid:100003145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"production.sparshims.com",nocase; classtype:trojan-activity; sid:100003146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"programaoperadoronline.com.br",nocase; classtype:trojan-activity; sid:100003147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"project.exquitec.com",nocase; classtype:trojan-activity; sid:100003148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promotapp.com",nocase; classtype:trojan-activity; sid:100003149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promotoradescomplica.com.br",nocase; classtype:trojan-activity; sid:100003150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promoversdubai.com",nocase; classtype:trojan-activity; sid:100003151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq.elin.co.za",nocase; classtype:trojan-activity; sid:100003152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq2.elin.co.za",nocase; classtype:trojan-activity; sid:100003153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosoc.nl",nocase; classtype:trojan-activity; sid:100003154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosupport.cl",nocase; classtype:trojan-activity; sid:100003155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosyarmakassar.com",nocase; classtype:trojan-activity; sid:100003156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"provence.elin.co.za",nocase; classtype:trojan-activity; sid:100003157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prueba.danielluza.com",nocase; classtype:trojan-activity; sid:100003158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pujashoppe.in",nocase; classtype:trojan-activity; sid:100003159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punchdialogues.com",nocase; classtype:trojan-activity; sid:100003160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punjabdevelopersassociation.com.pk",nocase; classtype:trojan-activity; sid:100003161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pvcprinting.co.uk",nocase; classtype:trojan-activity; sid:100003162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qadir.tickfa.ir",nocase; classtype:trojan-activity; sid:100003163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qatarglobalconsulting.com",nocase; classtype:trojan-activity; sid:100003164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qmsled.com",nocase; classtype:trojan-activity; sid:100003165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quartier-midi.be",nocase; classtype:trojan-activity; sid:100003166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"querocar.com",nocase; classtype:trojan-activity; sid:100003167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rachmat-assuhaimi.my.id",nocase; classtype:trojan-activity; sid:100003168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"radioafifense.deploys.live",nocase; classtype:trojan-activity; sid:100003169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rainbowisp.info",nocase; classtype:trojan-activity; sid:100003170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rajeshtailang.com",nocase; classtype:trojan-activity; sid:100003171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rakeshkhatri.in",nocase; classtype:trojan-activity; sid:100003172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raodigitalmedia.com",nocase; classtype:trojan-activity; sid:100003173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raquelhelena.com.br",nocase; classtype:trojan-activity; sid:100003174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rarlabarchiver.ac",nocase; classtype:trojan-activity; sid:100003175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rasadbar.ir",nocase; classtype:trojan-activity; sid:100003176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rashika.ascarvalho.co.za",nocase; classtype:trojan-activity; sid:100003177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ratemyfenancialadvisor.com",nocase; classtype:trojan-activity; sid:100003178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ravenproductionsltd.com",nocase; classtype:trojan-activity; sid:100003179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rc.ixiaoyang.cn",nocase; classtype:trojan-activity; sid:100003180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rcmesilva.charbelsales.com.br",nocase; classtype:trojan-activity; sid:100003181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reacredit.com.br",nocase; classtype:trojan-activity; sid:100003182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"readymmade.com",nocase; classtype:trojan-activity; sid:100003183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"recyclethesurplus.com",nocase; classtype:trojan-activity; sid:100003184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"redbats.co.in",nocase; classtype:trojan-activity; sid:100003185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"redchillicrackers.com",nocase; classtype:trojan-activity; sid:100003186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reifenquick.de",nocase; classtype:trojan-activity; sid:100003187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"relaxindulge.co.nz",nocase; classtype:trojan-activity; sid:100003188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"renehavis.com.ua",nocase; classtype:trojan-activity; sid:100003189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"repatriacioncolombia.com",nocase; classtype:trojan-activity; sid:100003190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.uf1.cn",nocase; classtype:trojan-activity; sid:100003191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reseller.digimitra.in",nocase; classtype:trojan-activity; sid:100003192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reseller.itechbrasil.com",nocase; classtype:trojan-activity; sid:100003193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"resuco.net",nocase; classtype:trojan-activity; sid:100003194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rezkabum.ru",nocase; classtype:trojan-activity; sid:100003195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rhema.com.sg",nocase; classtype:trojan-activity; sid:100003196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"richancyber.info",nocase; classtype:trojan-activity; sid:100003197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"richmondminerals.co.zm",nocase; classtype:trojan-activity; sid:100003198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinaefoundation.org.za",nocase; classtype:trojan-activity; sid:100003199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinkaisystem-ht.com",nocase; classtype:trojan-activity; sid:100003200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"riverfox.co.za",nocase; classtype:trojan-activity; sid:100003201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkcable.co.in",nocase; classtype:trojan-activity; sid:100003202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkverify.securestudies.com",nocase; classtype:trojan-activity; sid:100003203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertmcardle.com",nocase; classtype:trojan-activity; sid:100003204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertsinclair.net",nocase; classtype:trojan-activity; sid:100003205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"romanianpoints.com",nocase; classtype:trojan-activity; sid:100003206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ronnietucker.co.uk",nocase; classtype:trojan-activity; sid:100003207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roomsvc.servegate.kr",nocase; classtype:trojan-activity; sid:100003208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roshnijewellery.com",nocase; classtype:trojan-activity; sid:100003209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rsgym.net",nocase; classtype:trojan-activity; sid:100003210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubazar.pro",nocase; classtype:trojan-activity; sid:100003211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubycityvietnam.com",nocase; classtype:trojan-activity; sid:100003212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruisgood.ru",nocase; classtype:trojan-activity; sid:100003213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruwadalkuwait.com",nocase; classtype:trojan-activity; sid:100003214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rydchile.cl",nocase; classtype:trojan-activity; sid:100003215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.51shijuan.com",nocase; classtype:trojan-activity; sid:100003216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.thechinesemuslim.com",nocase; classtype:trojan-activity; sid:100003217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sac2.11xii.com",nocase; classtype:trojan-activity; sid:100003218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sacredscentsonline.com",nocase; classtype:trojan-activity; sid:100003219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sadmahfuneralservices.co.za",nocase; classtype:trojan-activity; sid:100003220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safcol-colors.com",nocase; classtype:trojan-activity; sid:100003221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safehubsecurity.ca",nocase; classtype:trojan-activity; sid:100003222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safety.nanotechproautocare.com",nocase; classtype:trojan-activity; sid:100003223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sahathaikasetpan.com",nocase; classtype:trojan-activity; sid:100003224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sainzim.co.za",nocase; classtype:trojan-activity; sid:100003225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"saisoftwareinc.com",nocase; classtype:trojan-activity; sid:100003226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"salecorner.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"salonsaifa.com",nocase; classtype:trojan-activity; sid:100003228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"samriddhijyotish.com",nocase; classtype:trojan-activity; sid:100003229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sandovalgraphics.com",nocase; classtype:trojan-activity; sid:100003230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"santyago.org",nocase; classtype:trojan-activity; sid:100003231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sasystemsuk.com",nocase; classtype:trojan-activity; sid:100003232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scaladevelopments.scaladevco.com",nocase; classtype:trojan-activity; sid:100003233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scarfaceindustries.com",nocase; classtype:trojan-activity; sid:100003234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scglobal.co.th",nocase; classtype:trojan-activity; sid:100003235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schalke04rss.de",nocase; classtype:trojan-activity; sid:100003236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scheff.com",nocase; classtype:trojan-activity; sid:100003237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schoolbustracker.softgig.co.ke",nocase; classtype:trojan-activity; sid:100003238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sculetus.nl",nocase; classtype:trojan-activity; sid:100003239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"secure-doc-reader.com",nocase; classtype:trojan-activity; sid:100003240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"segalsmetals.elin.co.za",nocase; classtype:trojan-activity; sid:100003241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sellmyphonela.com",nocase; classtype:trojan-activity; sid:100003242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"selltechtoday.com",nocase; classtype:trojan-activity; sid:100003243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"senbiaojita.com",nocase; classtype:trojan-activity; sid:100003244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sentierodelviandante.ml",nocase; classtype:trojan-activity; sid:100003245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"serendibsourcing.com",nocase; classtype:trojan-activity; sid:100003246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sericaasia.com",nocase; classtype:trojan-activity; sid:100003247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd.myvnc.com",nocase; classtype:trojan-activity; sid:100003248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd80.myvnc.com",nocase; classtype:trojan-activity; sid:100003249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sexologistpakistan.net",nocase; classtype:trojan-activity; sid:100003250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sgb.ac.ke",nocase; classtype:trojan-activity; sid:100003251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sgessy.com.br",nocase; classtype:trojan-activity; sid:100003252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shaheentbfoundation.com",nocase; classtype:trojan-activity; sid:100003253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shahikhana.cstdevs.com",nocase; classtype:trojan-activity; sid:100003254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shahu66.com",nocase; classtype:trojan-activity; sid:100003255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharkrigs.com",nocase; classtype:trojan-activity; sid:100003256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharpelevators.in",nocase; classtype:trojan-activity; sid:100003257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shembefoundation.com",nocase; classtype:trojan-activity; sid:100003258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shivakunwar.com.np",nocase; classtype:trojan-activity; sid:100003259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shoblasaathitrust.org",nocase; classtype:trojan-activity; sid:100003260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shooka-co.com",nocase; classtype:trojan-activity; sid:100003261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shop.goldspot.agency",nocase; classtype:trojan-activity; sid:100003262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shopsofe.com",nocase; classtype:trojan-activity; sid:100003263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shrinikelectrical.co.za",nocase; classtype:trojan-activity; sid:100003264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sibernetix.fr",nocase; classtype:trojan-activity; sid:100003265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sige.brisainformatica.com.br",nocase; classtype:trojan-activity; sid:100003266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"signatureads.co.in",nocase; classtype:trojan-activity; sid:100003267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siili.net",nocase; classtype:trojan-activity; sid:100003268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simoneporzi.it",nocase; classtype:trojan-activity; sid:100003269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simorsint.com",nocase; classtype:trojan-activity; sid:100003270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simplithy.co.uk",nocase; classtype:trojan-activity; sid:100003271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindicato1ucm.cl",nocase; classtype:trojan-activity; sid:100003272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindpol.tiejuris.com.br",nocase; classtype:trojan-activity; sid:100003273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sinergidwireka.com",nocase; classtype:trojan-activity; sid:100003274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sipahielektrik.com",nocase; classtype:trojan-activity; sid:100003275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sistelligent.com",nocase; classtype:trojan-activity; sid:100003276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skare.net",nocase; classtype:trojan-activity; sid:100003277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyflyfares.com",nocase; classtype:trojan-activity; sid:100003278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyscan.com",nocase; classtype:trojan-activity; sid:100003279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smarthouseforum.ru",nocase; classtype:trojan-activity; sid:100003280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smartzedu.com",nocase; classtype:trojan-activity; sid:100003281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smokesolutionindia.com",nocase; classtype:trojan-activity; sid:100003282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smritiphotography.in",nocase; classtype:trojan-activity; sid:100003283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sobariko.com",nocase; classtype:trojan-activity; sid:100003284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sobethuacademy.com",nocase; classtype:trojan-activity; sid:100003285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.110route.com",nocase; classtype:trojan-activity; sid:100003286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.officelabo.net",nocase; classtype:trojan-activity; sid:100003287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"softanis.net",nocase; classtype:trojan-activity; sid:100003288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sogecoenergy.com",nocase; classtype:trojan-activity; sid:100003289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sohs.conceptechs.info",nocase; classtype:trojan-activity; sid:100003290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"solar.amazingtribe.lk",nocase; classtype:trojan-activity; sid:100003291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somcorbera.cat",nocase; classtype:trojan-activity; sid:100003292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somir.com.mx",nocase; classtype:trojan-activity; sid:100003293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soralapps.com",nocase; classtype:trojan-activity; sid:100003294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sota-france.fr",nocase; classtype:trojan-activity; sid:100003295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"space.proactint.org",nocase; classtype:trojan-activity; sid:100003296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spaceframe.mobi.space-frame.co.za",nocase; classtype:trojan-activity; sid:100003297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"special-key.cf",nocase; classtype:trojan-activity; sid:100003298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spent.com.pl",nocase; classtype:trojan-activity; sid:100003299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spetsesyachtcharter.gr",nocase; classtype:trojan-activity; sid:100003300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spititourism.com",nocase; classtype:trojan-activity; sid:100003301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spittinfire.com",nocase; classtype:trojan-activity; sid:100003302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sports-net.de",nocase; classtype:trojan-activity; sid:100003303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"src1.minibai.com",nocase; classtype:trojan-activity; sid:100003304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sreenivasapaintingworks.com",nocase; classtype:trojan-activity; sid:100003305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sriglobalit.com",nocase; classtype:trojan-activity; sid:100003306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"srilankamovies.com",nocase; classtype:trojan-activity; sid:100003307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"srvmanos.no-ip.info",nocase; classtype:trojan-activity; sid:100003308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ss.monita.co.id",nocase; classtype:trojan-activity; sid:100003309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"st.devcodin.com",nocase; classtype:trojan-activity; sid:100003310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"staging.apparelpunch.com",nocase; classtype:trojan-activity; sid:100003311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"starcountry.net",nocase; classtype:trojan-activity; sid:100003312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"static.3001.net",nocase; classtype:trojan-activity; sid:100003313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stiau.iuc.ac",nocase; classtype:trojan-activity; sid:100003314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sticker.jewsjuice.com",nocase; classtype:trojan-activity; sid:100003315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stiepancasetia.ac.id",nocase; classtype:trojan-activity; sid:100003316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stlukesohag.com",nocase; classtype:trojan-activity; sid:100003317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"store.ericalgarin.com",nocase; classtype:trojan-activity; sid:100003318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stott-thompson.co.uk",nocase; classtype:trojan-activity; sid:100003319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"streetdemo.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"suboldesign.com",nocase; classtype:trojan-activity; sid:100003321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sumerians.org",nocase; classtype:trojan-activity; sid:100003322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunaryem.com.tr",nocase; classtype:trojan-activity; sid:100003323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunbrero.com.au",nocase; classtype:trojan-activity; sid:100003324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunmarkholidays.com",nocase; classtype:trojan-activity; sid:100003325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"supermercadostia.com",nocase; classtype:trojan-activity; sid:100003326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support-4-free.com",nocase; classtype:trojan-activity; sid:100003327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support.clz.kr",nocase; classtype:trojan-activity; sid:100003328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"supportit.online",nocase; classtype:trojan-activity; sid:100003329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sw.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweaty.dk",nocase; classtype:trojan-activity; sid:100003331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweet-diet.com",nocase; classtype:trojan-activity; sid:100003332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swiftlogisticseg.com",nocase; classtype:trojan-activity; sid:100003333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swwbia.com",nocase; classtype:trojan-activity; sid:100003334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"syracusecoffee.com",nocase; classtype:trojan-activity; sid:100003335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sytraders.co",nocase; classtype:trojan-activity; sid:100003336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"t.honker.info",nocase; classtype:trojan-activity; sid:100003337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"t.netcatkit.com",nocase; classtype:trojan-activity; sid:100003338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tacticohosting.com",nocase; classtype:trojan-activity; sid:100003339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tadoo.ca",nocase; classtype:trojan-activity; sid:100003340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tafsantoursandtravels.com",nocase; classtype:trojan-activity; sid:100003341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tajushariya.com",nocase; classtype:trojan-activity; sid:100003342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tallyinvoicecustomization.com",nocase; classtype:trojan-activity; sid:100003343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taltus.co.uk",nocase; classtype:trojan-activity; sid:100003344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tapalkoedacoffee.com",nocase; classtype:trojan-activity; sid:100003345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tarravalleyfoods.com.au",nocase; classtype:trojan-activity; sid:100003346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taurus.ug",nocase; classtype:trojan-activity; sid:100003347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tavo.cl",nocase; classtype:trojan-activity; sid:100003348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taxicabsrilanka.com",nocase; classtype:trojan-activity; sid:100003349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tc.snpsresidential.com",nocase; classtype:trojan-activity; sid:100003350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tcy.198424.com",nocase; classtype:trojan-activity; sid:100003351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tdsp.yngw518.com",nocase; classtype:trojan-activity; sid:100003352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tech332.synology.me",nocase; classtype:trojan-activity; sid:100003353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"techgms.com",nocase; classtype:trojan-activity; sid:100003354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teduae.com",nocase; classtype:trojan-activity; sid:100003355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teleargentina.com",nocase; classtype:trojan-activity; sid:100003356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"telescopelms.com",nocase; classtype:trojan-activity; sid:100003357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tencoconsulting.com",nocase; classtype:trojan-activity; sid:100003358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teneth.co.za",nocase; classtype:trojan-activity; sid:100003359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tentandoserfitness.000webhostapp.com",nocase; classtype:trojan-activity; sid:100003360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tessrobins.com",nocase; classtype:trojan-activity; sid:100003361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.adventser.com",nocase; classtype:trojan-activity; sid:100003362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.letraele.es",nocase; classtype:trojan-activity; sid:100003363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.lubrico.in",nocase; classtype:trojan-activity; sid:100003364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.typoten.com",nocase; classtype:trojan-activity; sid:100003365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.wanepghana.org",nocase; classtype:trojan-activity; sid:100003366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.asistencia247.com",nocase; classtype:trojan-activity; sid:100003367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.tenplusone.my",nocase; classtype:trojan-activity; sid:100003368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.basis-web.com",nocase; classtype:trojan-activity; sid:100003369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.marrenconstruction.ie",nocase; classtype:trojan-activity; sid:100003370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.clickitsolutionsmw.com",nocase; classtype:trojan-activity; sid:100003371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.thinkingcorp.in",nocase; classtype:trojan-activity; sid:100003372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testnew.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testuat.itmoregistry.com",nocase; classtype:trojan-activity; sid:100003374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teteaffiche.stephanebillon.com",nocase; classtype:trojan-activity; sid:100003375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tewoerd.eu",nocase; classtype:trojan-activity; sid:100003376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"textile.softberg.ro",nocase; classtype:trojan-activity; sid:100003377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tharringtonsponsorship.com",nocase; classtype:trojan-activity; sid:100003378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theatretalkies.in",nocase; classtype:trojan-activity; sid:100003379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecleaningladiespdx.com",nocase; classtype:trojan-activity; sid:100003380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecreativecafe.co.uk",nocase; classtype:trojan-activity; sid:100003381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thedesertship.com",nocase; classtype:trojan-activity; sid:100003382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thediasporianexperience.com",nocase; classtype:trojan-activity; sid:100003383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thefirmlawgroup.com.au",nocase; classtype:trojan-activity; sid:100003384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thefuturelife.in",nocase; classtype:trojan-activity; sid:100003385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thehighlightinterior.com",nocase; classtype:trojan-activity; sid:100003386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thekassia.co.uk",nocase; classtype:trojan-activity; sid:100003387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"themansionkasauli.com",nocase; classtype:trojan-activity; sid:100003388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theprofinn.com",nocase; classtype:trojan-activity; sid:100003389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thesummitpc.net",nocase; classtype:trojan-activity; sid:100003390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theurbantutors.com",nocase; classtype:trojan-activity; sid:100003391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thientu.net",nocase; classtype:trojan-activity; sid:100003392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thosewebbs.com",nocase; classtype:trojan-activity; sid:100003393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thriveink.com",nocase; classtype:trojan-activity; sid:100003394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tianangdep.com",nocase; classtype:trojan-activity; sid:100003395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickfoods.tickme.lk",nocase; classtype:trojan-activity; sid:100003396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tienda.ventadigital.com.ar",nocase; classtype:trojan-activity; sid:100003397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"timamollo.co.za",nocase; classtype:trojan-activity; sid:100003398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"timegonebuy.com",nocase; classtype:trojan-activity; sid:100003399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tksb.net",nocase; classtype:trojan-activity; sid:100003400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tlcc.com.gt",nocase; classtype:trojan-activity; sid:100003401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tntmedia.gr",nocase; classtype:trojan-activity; sid:100003402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"todoapp.cstdevs.com",nocase; classtype:trojan-activity; sid:100003403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"todocontodo.com.mx",nocase; classtype:trojan-activity; sid:100003404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonydong.com",nocase; classtype:trojan-activity; sid:100003405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonystram.com",nocase; classtype:trojan-activity; sid:100003406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonyzone.com",nocase; classtype:trojan-activity; sid:100003407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tooba.tenplusone.my",nocase; classtype:trojan-activity; sid:100003408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tools.reimclub.com",nocase; classtype:trojan-activity; sid:100003409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topcell9.com",nocase; classtype:trojan-activity; sid:100003410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toplevel.com.br",nocase; classtype:trojan-activity; sid:100003411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topmask.co.za",nocase; classtype:trojan-activity; sid:100003412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"torresquinterocorp.com",nocase; classtype:trojan-activity; sid:100003413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toyotacollege.ac.th",nocase; classtype:trojan-activity; sid:100003414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpef.lsoftdemo.com",nocase; classtype:trojan-activity; sid:100003415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpke.hu",nocase; classtype:trojan-activity; sid:100003416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"translaterjemah.com",nocase; classtype:trojan-activity; sid:100003417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"travelwithmanta.co.za",nocase; classtype:trojan-activity; sid:100003418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trendyshoes.co.za",nocase; classtype:trojan-activity; sid:100003419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trezors.io.mahlongwa.com",nocase; classtype:trojan-activity; sid:100003420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trimestre.bar",nocase; classtype:trojan-activity; sid:100003421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"triplonet.com.br",nocase; classtype:trojan-activity; sid:100003422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"troki.com.co",nocase; classtype:trojan-activity; sid:100003423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tropics.codeleek.net",nocase; classtype:trojan-activity; sid:100003424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trudelfavreau.com",nocase; classtype:trojan-activity; sid:100003425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsd.jxwan.com",nocase; classtype:trojan-activity; sid:100003426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tulli.info",nocase; classtype:trojan-activity; sid:100003427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tupperware.michaelroberge.ca",nocase; classtype:trojan-activity; sid:100003428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"turanggaresources.com",nocase; classtype:trojan-activity; sid:100003429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"txtdust.com",nocase; classtype:trojan-activity; sid:100003430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uat.indianfilmzone.com",nocase; classtype:trojan-activity; sid:100003431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ublretailerdemo.cstdevs.com",nocase; classtype:trojan-activity; sid:100003432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uc-56.ru",nocase; classtype:trojan-activity; sid:100003433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uisusa.uisusa.com",nocase; classtype:trojan-activity; sid:100003434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ultimate-24.de",nocase; classtype:trojan-activity; sid:100003435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"umwelt-kirchhof.de",nocase; classtype:trojan-activity; sid:100003436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unicorpbrunei.com",nocase; classtype:trojan-activity; sid:100003437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uniengrisb.com",nocase; classtype:trojan-activity; sid:100003438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unyazitelecom.com",nocase; classtype:trojan-activity; sid:100003439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"upcbpta.com",nocase; classtype:trojan-activity; sid:100003440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"urbantrapfest.cl",nocase; classtype:trojan-activity; sid:100003441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"usamyforever.azureedge.net",nocase; classtype:trojan-activity; sid:100003442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"used-jeans.fr",nocase; classtype:trojan-activity; sid:100003443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"useformoney.000webhostapp.com",nocase; classtype:trojan-activity; sid:100003444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"usmadetshirts.com",nocase; classtype:trojan-activity; sid:100003445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uss.ac.th",nocase; classtype:trojan-activity; sid:100003446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uzzepay.com.br",nocase; classtype:trojan-activity; sid:100003447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vanzare.cabanabrazi2.ro",nocase; classtype:trojan-activity; sid:100003448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vbcargo.hu",nocase; classtype:trojan-activity; sid:100003449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vcah.co.uk",nocase; classtype:trojan-activity; sid:100003450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vectarts.com",nocase; classtype:trojan-activity; sid:100003451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vegadelcasero.cl",nocase; classtype:trojan-activity; sid:100003452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vendas.lidiacarmeli.com.br",nocase; classtype:trojan-activity; sid:100003453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"veterinariadrpopui.com",nocase; classtype:trojan-activity; sid:100003454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vfocus.net",nocase; classtype:trojan-activity; sid:100003455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vienen.gblix.srv.br",nocase; classtype:trojan-activity; sid:100003456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vilaart.rs",nocase; classtype:trojan-activity; sid:100003457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villamarand.com",nocase; classtype:trojan-activity; sid:100003458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villatera.com",nocase; classtype:trojan-activity; sid:100003459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"violinstop.com",nocase; classtype:trojan-activity; sid:100003460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"virtuleverage.com",nocase; classtype:trojan-activity; sid:100003461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visions.alnisamart.com",nocase; classtype:trojan-activity; sid:100003462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visualhome.cl",nocase; classtype:trojan-activity; sid:100003463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vitoriamodaintima.com.br",nocase; classtype:trojan-activity; sid:100003464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vivationdesign.com",nocase; classtype:trojan-activity; sid:100003465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"viveirodoiscorregos.com.br",nocase; classtype:trojan-activity; sid:100003466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vksales.com",nocase; classtype:trojan-activity; sid:100003467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vocalterra.com",nocase; classtype:trojan-activity; sid:100003468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vokasi.ub.ac.id",nocase; classtype:trojan-activity; sid:100003469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vologroup.com.br",nocase; classtype:trojan-activity; sid:100003470; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"voteyouramerica.dekitout.com",nocase; classtype:trojan-activity; sid:100003471; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vpinversiones.cl",nocase; classtype:trojan-activity; sid:100003472; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vpts.co.za",nocase; classtype:trojan-activity; sid:100003473; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vstsample.com",nocase; classtype:trojan-activity; sid:100003474; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vtube.fadlymotivator.com",nocase; classtype:trojan-activity; sid:100003475; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vvsskmodinationalschool.com",nocase; classtype:trojan-activity; sid:100003476; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu",nocase; classtype:trojan-activity; sid:100003477; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepliberia.org",nocase; classtype:trojan-activity; sid:100003478; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepniger.org",nocase; classtype:trojan-activity; sid:100003479; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.eng.ubu.ac.th",nocase; classtype:trojan-activity; sid:100003480; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.geetle.ga",nocase; classtype:trojan-activity; sid:100003481; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.geomegasoft.net",nocase; classtype:trojan-activity; sid:100003482; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.newinnovationtechnology.com",nocase; classtype:trojan-activity; sid:100003483; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.smarts-works.com",nocase; classtype:trojan-activity; sid:100003484; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.thebeessolution.com",nocase; classtype:trojan-activity; sid:100003485; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webgis.perumdasolo.com",nocase; classtype:trojan-activity; sid:100003486; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webmailwindstreamnetmessagesecureapp1rqr.ga",nocase; classtype:trojan-activity; sid:100003487; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webpresario.com",nocase; classtype:trojan-activity; sid:100003488; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"website-work.com",nocase; classtype:trojan-activity; sid:100003489; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weinsteincounseling.com",nocase; classtype:trojan-activity; sid:100003490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wfinance.com.br",nocase; classtype:trojan-activity; sid:100003491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whcms.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whiteresponse.com",nocase; classtype:trojan-activity; sid:100003493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wi522012.ferozo.com",nocase; classtype:trojan-activity; sid:100003494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikalen.co.za",nocase; classtype:trojan-activity; sid:100003495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildnights.co.uk",nocase; classtype:trojan-activity; sid:100003496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildtrust.mediadevstaging.com",nocase; classtype:trojan-activity; sid:100003497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"willow-nettica.com",nocase; classtype:trojan-activity; sid:100003498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wimbamusica.com",nocase; classtype:trojan-activity; sid:100003499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"windcomtechnologies.com",nocase; classtype:trojan-activity; sid:100003500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wishesconcierge.com",nocase; classtype:trojan-activity; sid:100003501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woezon.agency",nocase; classtype:trojan-activity; sid:100003502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wolfgang-brodte.de",nocase; classtype:trojan-activity; sid:100003503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wonderhawaii.com",nocase; classtype:trojan-activity; sid:100003504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woodsytech.com",nocase; classtype:trojan-activity; sid:100003505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wordpress.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100003506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wozata.000webhostapp.com",nocase; classtype:trojan-activity; sid:100003507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wp.readhere.in",nocase; classtype:trojan-activity; sid:100003508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wpdemo.101clients.com.au",nocase; classtype:trojan-activity; sid:100003509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"writtendeer.com",nocase; classtype:trojan-activity; sid:100003510; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ws5588.f3322.net",nocase; classtype:trojan-activity; sid:100003511; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wsdyrmtcntlfarmtwsvb.dns.army",nocase; classtype:trojan-activity; sid:100003512; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wyklej.pl",nocase; classtype:trojan-activity; sid:100003513; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"x-iting.de",nocase; classtype:trojan-activity; sid:100003514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"x2vn.com",nocase; classtype:trojan-activity; sid:100003515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xia.beihaixue.com",nocase; classtype:trojan-activity; sid:100003516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xixaoclothing.com",nocase; classtype:trojan-activity; sid:100003517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xk.996is.com",nocase; classtype:trojan-activity; sid:100003518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--80akinnkiib6h.xn--90ais",nocase; classtype:trojan-activity; sid:100003519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--polimerbizmimarlk-rvc.com",nocase; classtype:trojan-activity; sid:100003520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ybom.urbanolab.com",nocase; classtype:trojan-activity; sid:100003521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yeichner.com",nocase; classtype:trojan-activity; sid:100003522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ylfpremium.com",nocase; classtype:trojan-activity; sid:100003523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yoast.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yourclub1.com",nocase; classtype:trojan-activity; sid:100003525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yourtopdog.com.au",nocase; classtype:trojan-activity; sid:100003526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"youtubetrainingacademy.com",nocase; classtype:trojan-activity; sid:100003527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yp.hnggzyjy.cn",nocase; classtype:trojan-activity; sid:100003528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yskadvisors.com",nocase; classtype:trojan-activity; sid:100003529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yummyyogaudaipur.com",nocase; classtype:trojan-activity; sid:100003530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yzkzixun.com",nocase; classtype:trojan-activity; sid:100003531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zmedcoach.com",nocase; classtype:trojan-activity; sid:100003532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zytrox.tk",nocase; classtype:trojan-activity; sid:100003533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zz.690tx.com",nocase; classtype:trojan-activity; sid:100003534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100003535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/86.exe",nocase; classtype:trojan-activity; sid:100003536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/c64.exe",nocase; classtype:trojan-activity; sid:100003537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amumufree.weebly.com",nocase; http_uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe",nocase; classtype:trojan-activity; sid:100003538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"analogx.com",nocase; http_uri; content:"/files/proxyi.exe",nocase; classtype:trojan-activity; sid:100003539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe",nocase; classtype:trojan-activity; sid:100003540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/dvdfv/anjj/downloads/jami.exe",nocase; classtype:trojan-activity; sid:100003541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/johnhast/efve/downloads/versiumr.exe",nocase; classtype:trojan-activity; sid:100003542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/johnhast/efve/downloads/versiumrr.exe",nocase; classtype:trojan-activity; sid:100003543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/4.exe",nocase; classtype:trojan-activity; sid:100003544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/6.exe",nocase; classtype:trojan-activity; sid:100003545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/labesoftware/update/downloads/boost-fps.exe",nocase; classtype:trojan-activity; sid:100003546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/labesoftware/update/downloads/install_plugin_x64_x86.exe",nocase; classtype:trojan-activity; sid:100003547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/labesoftware/update/downloads/vpn_free.exe",nocase; classtype:trojan-activity; sid:100003548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/clr.exe",nocase; classtype:trojan-activity; sid:100003549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatev.exe",nocase; classtype:trojan-activity; sid:100003550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/work.exe",nocase; classtype:trojan-activity; sid:100003551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/component.exe",nocase; classtype:trojan-activity; sid:100003552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe",nocase; classtype:trojan-activity; sid:100003553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/regsvc.exe",nocase; classtype:trojan-activity; sid:100003554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/skygaming/updates/downloads/update.exe",nocase; classtype:trojan-activity; sid:100003555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/001.txt",nocase; classtype:trojan-activity; sid:100003556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1488.txt",nocase; classtype:trojan-activity; sid:100003557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1_cr.txt",nocase; classtype:trojan-activity; sid:100003558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1cr.txt",nocase; classtype:trojan-activity; sid:100003559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1fc2d.txt",nocase; classtype:trojan-activity; sid:100003560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/26a5.txt",nocase; classtype:trojan-activity; sid:100003561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt",nocase; classtype:trojan-activity; sid:100003562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/abjects.txt",nocase; classtype:trojan-activity; sid:100003563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/attached.txt",nocase; classtype:trojan-activity; sid:100003564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/b7f2c.exe",nocase; classtype:trojan-activity; sid:100003565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/battletext.txt",nocase; classtype:trojan-activity; sid:100003566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe",nocase; classtype:trojan-activity; sid:100003567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe",nocase; classtype:trojan-activity; sid:100003568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build.txt",nocase; classtype:trojan-activity; sid:100003569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_makros.exe",nocase; classtype:trojan-activity; sid:100003570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_silent.txt",nocase; classtype:trojan-activity; sid:100003571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_sup.txt",nocase; classtype:trojan-activity; sid:100003572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe",nocase; classtype:trojan-activity; sid:100003573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt",nocase; classtype:trojan-activity; sid:100003574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcr.txt",nocase; classtype:trojan-activity; sid:100003575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildss.txt",nocase; classtype:trojan-activity; sid:100003576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientnik.txt",nocase; classtype:trojan-activity; sid:100003577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientrevers.txt",nocase; classtype:trojan-activity; sid:100003578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dcrat.exe",nocase; classtype:trojan-activity; sid:100003579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices.exe",nocase; classtype:trojan-activity; sid:100003580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices2.exe",nocase; classtype:trojan-activity; sid:100003581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe",nocase; classtype:trojan-activity; sid:100003582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hans.txt",nocase; classtype:trojan-activity; sid:100003583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hulu.txt",nocase; classtype:trojan-activity; sid:100003584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfive.txt",nocase; classtype:trojan-activity; sid:100003585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfour.txt",nocase; classtype:trojan-activity; sid:100003586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelone.txt",nocase; classtype:trojan-activity; sid:100003587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelthree.txt",nocase; classtype:trojan-activity; sid:100003588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/inteltwo.txt",nocase; classtype:trojan-activity; sid:100003589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe",nocase; classtype:trojan-activity; sid:100003590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/kleiman.exe",nocase; classtype:trojan-activity; sid:100003591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe",nocase; classtype:trojan-activity; sid:100003592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/notepadplus.txt",nocase; classtype:trojan-activity; sid:100003593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe",nocase; classtype:trojan-activity; sid:100003594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.exe",nocase; classtype:trojan-activity; sid:100003595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.txt",nocase; classtype:trojan-activity; sid:100003596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt",nocase; classtype:trojan-activity; sid:100003597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/putty.txt",nocase; classtype:trojan-activity; sid:100003598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/rockethcd.txt",nocase; classtype:trojan-activity; sid:100003599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/scvhost900.exe",nocase; classtype:trojan-activity; sid:100003600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/sessionwin.exe",nocase; classtype:trojan-activity; sid:100003601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/siliculose.txt",nocase; classtype:trojan-activity; sid:100003602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/statemobi.txt",nocase; classtype:trojan-activity; sid:100003603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers.exe",nocase; classtype:trojan-activity; sid:100003604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers2.exe",nocase; classtype:trojan-activity; sid:100003605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stgedo.exe",nocase; classtype:trojan-activity; sid:100003606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/svcperf.txt",nocase; classtype:trojan-activity; sid:100003607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe",nocase; classtype:trojan-activity; sid:100003608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurjok.txt",nocase; classtype:trojan-activity; sid:100003609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurusbabac.exe",nocase; classtype:trojan-activity; sid:100003610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/telekiller.exe",nocase; classtype:trojan-activity; sid:100003611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateanddr.txt",nocase; classtype:trojan-activity; sid:100003612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateandr.txt",nocase; classtype:trojan-activity; sid:100003613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/vhajeja.txt",nocase; classtype:trojan-activity; sid:100003614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/word.txt",nocase; classtype:trojan-activity; sid:100003615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/www.txt",nocase; classtype:trojan-activity; sid:100003616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/xlsd.txt",nocase; classtype:trojan-activity; sid:100003617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin",nocase; classtype:trojan-activity; sid:100003618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin",nocase; classtype:trojan-activity; sid:100003619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cd.textfiles.com",nocase; http_uri; content:"/hmatrix/data/hack1226.exe",nocase; classtype:trojan-activity; sid:100003620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq",nocase; classtype:trojan-activity; sid:100003621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/816070119281131570/816070273254162442/all.txt",nocase; classtype:trojan-activity; sid:100003622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/825372018244583454/826848185246023750/loaddd.exe",nocase; classtype:trojan-activity; sid:100003623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/825372018244583454/826848348342059008/zeppelin.exe",nocase; classtype:trojan-activity; sid:100003624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/825372018244583454/826848405258633277/build.exe",nocase; classtype:trojan-activity; sid:100003625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/826198252025675816/826537386485612574/china.png",nocase; classtype:trojan-activity; sid:100003626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin",nocase; classtype:trojan-activity; sid:100003627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe",nocase; classtype:trojan-activity; sid:100003628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chiptune.com",nocase; http_uri; content:"/razor/rzr-winner_intro.zip",nocase; classtype:trojan-activity; sid:100003629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz",nocase; classtype:trojan-activity; sid:100003630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar",nocase; classtype:trojan-activity; sid:100003631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codeload.github.com",nocase; http_uri; content:"/meteoradminz/hidden-tear/zip/master",nocase; classtype:trojan-activity; sid:100003632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colfincas.com",nocase; http_uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/",nocase; classtype:trojan-activity; sid:100003633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deepfreedom.org",nocase; http_uri; content:"/qz0h69.pdf",nocase; classtype:trojan-activity; sid:100003634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?export=download&id=1ktcghnmcwws43wzscphukbfnwtuaxidx&revid=0b8z0b7_i5sirk2xrtehmstg0vxvit3b4n3lmbdrdrjrodndrpq",nocase; classtype:trojan-activity; sid:100003635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com.it-barcelona.com",nocase; http_uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe",nocase; classtype:trojan-activity; sid:100003636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm",nocase; classtype:trojan-activity; sid:100003637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=12khl-unz2np4q54b2jgpwlsh6cuz0pss",nocase; classtype:trojan-activity; sid:100003638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=13sfskplrox3d7uantwjj_trs6ciwvqa1",nocase; classtype:trojan-activity; sid:100003639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch",nocase; classtype:trojan-activity; sid:100003640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=152yoztzpbx_bbpxepfackfklg8c1eao6",nocase; classtype:trojan-activity; sid:100003641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=15hcgek7odccdafzf-9gvibnlgkirj4uo",nocase; classtype:trojan-activity; sid:100003642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox",nocase; classtype:trojan-activity; sid:100003643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=194lqzukzvt-jtdxmihcvhd0yk1sxoybk",nocase; classtype:trojan-activity; sid:100003644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig",nocase; classtype:trojan-activity; sid:100003645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn",nocase; classtype:trojan-activity; sid:100003646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1br5iufkkmmfeipqo3ecviqykbcdgcnio",nocase; classtype:trojan-activity; sid:100003647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv",nocase; classtype:trojan-activity; sid:100003648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1cos43rmscrescxk3u40qjuqbwr-pydsn",nocase; classtype:trojan-activity; sid:100003649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben",nocase; classtype:trojan-activity; sid:100003650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1dhoxtwbb2ycn8q06gi3p-ao_llldff0e",nocase; classtype:trojan-activity; sid:100003651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1dnm3wtjf6ud5fv6zop9cvbr4rs2of1-n",nocase; classtype:trojan-activity; sid:100003652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1dqin1sdd6rbah3sggzsxzeqgrkmhjnqm",nocase; classtype:trojan-activity; sid:100003653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi",nocase; classtype:trojan-activity; sid:100003654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1fensc6gc0fww0gbevsrnwwnlajypzdvv",nocase; classtype:trojan-activity; sid:100003655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1htinwtfrw1wc3_ma8odztnq0qpnic2q6",nocase; classtype:trojan-activity; sid:100003656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei",nocase; classtype:trojan-activity; sid:100003657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je",nocase; classtype:trojan-activity; sid:100003658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr",nocase; classtype:trojan-activity; sid:100003659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1jkov2g5s1xkcq4bfb3uvmd6inhadatrg",nocase; classtype:trojan-activity; sid:100003660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1jnarxelz8gtbkg5pa_s0rc8kv3ejkepn",nocase; classtype:trojan-activity; sid:100003661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1kjcylye1dbmhystyyotz-3pagktkhlhq",nocase; classtype:trojan-activity; sid:100003662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1lsv4sko083sywwjndgqnsh_6sgqodqtu",nocase; classtype:trojan-activity; sid:100003663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1mwgdd3lxuuk-bnsrm1rpclom0cmx7wob",nocase; classtype:trojan-activity; sid:100003664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y",nocase; classtype:trojan-activity; sid:100003665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd",nocase; classtype:trojan-activity; sid:100003666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1nmf6kty3xsoygjxjhb-bsafvlfy-0lt2",nocase; classtype:trojan-activity; sid:100003667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw",nocase; classtype:trojan-activity; sid:100003668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1p5fvqkxzwoiu_uauzbmrxpklsetculad",nocase; classtype:trojan-activity; sid:100003669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej",nocase; classtype:trojan-activity; sid:100003670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1q1dwckludrpqijtrpw14_60d5nu7n97t",nocase; classtype:trojan-activity; sid:100003671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1r9f9irwhutxozsbp2h9erd_a7fa2pwko",nocase; classtype:trojan-activity; sid:100003672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1s221a6wpx6i7nfrztnhh9priojtybuxq",nocase; classtype:trojan-activity; sid:100003673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1sjvkrinuscxqmbkdeusxaezazbiagnv3",nocase; classtype:trojan-activity; sid:100003674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1so1trfuzt5-giahetghfhmd-_ot3rq35",nocase; classtype:trojan-activity; sid:100003675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn",nocase; classtype:trojan-activity; sid:100003676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw",nocase; classtype:trojan-activity; sid:100003677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1uowridpynurgqlgqjbtgramigo2a9v76",nocase; classtype:trojan-activity; sid:100003678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55",nocase; classtype:trojan-activity; sid:100003679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t",nocase; classtype:trojan-activity; sid:100003680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vjq92eqivh01yxmal20whl2es3ld6nxb",nocase; classtype:trojan-activity; sid:100003681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e",nocase; classtype:trojan-activity; sid:100003682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi",nocase; classtype:trojan-activity; sid:100003683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58",nocase; classtype:trojan-activity; sid:100003684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi",nocase; classtype:trojan-activity; sid:100003685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv",nocase; classtype:trojan-activity; sid:100003686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yqpuxjbnjokc5fjgt-8xzuybr97rtvg2",nocase; classtype:trojan-activity; sid:100003687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ywkgalidldb32pio6ywmbyvdk7oar3yy",nocase; classtype:trojan-activity; sid:100003688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr",nocase; classtype:trojan-activity; sid:100003689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0",nocase; classtype:trojan-activity; sid:100003690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/1zilg/",nocase; classtype:trojan-activity; sid:100003691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/qcgfmfvh/",nocase; classtype:trojan-activity; sid:100003692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-mudhra.com",nocase; http_uri; content:"/downloads/emclick.zip",nocase; classtype:trojan-activity; sid:100003693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/",nocase; classtype:trojan-activity; sid:100003694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/",nocase; classtype:trojan-activity; sid:100003695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/x/",nocase; classtype:trojan-activity; sid:100003696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/",nocase; classtype:trojan-activity; sid:100003697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//",nocase; classtype:trojan-activity; sid:100003698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///",nocase; classtype:trojan-activity; sid:100003699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////",nocase; classtype:trojan-activity; sid:100003700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"file.elecfans.com",nocase; http_uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe",nocase; classtype:trojan-activity; sid:100003701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls",nocase; classtype:trojan-activity; sid:100003702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx",nocase; classtype:trojan-activity; sid:100003703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gist.githubusercontent.com",nocase; http_uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe",nocase; classtype:trojan-activity; sid:100003704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hqdecig.com",nocase; http_uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/",nocase; classtype:trojan-activity; sid:100003705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsecaravans.co.uk",nocase; http_uri; content:"/wp-admin/suy/",nocase; classtype:trojan-activity; sid:100003706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ia801802.us.archive.org",nocase; http_uri; content:"/19/items/startup_20210219/startup.txt",nocase; classtype:trojan-activity; sid:100003707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ie-best.net",nocase; http_uri; content:"/online-timer-kvhxz/ilxl/",nocase; classtype:trojan-activity; sid:100003708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100003709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/c64.exe",nocase; classtype:trojan-activity; sid:100003710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jcedu.org",nocase; http_uri; content:"/ebook/cs17.exe",nocase; classtype:trojan-activity; sid:100003711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1",nocase; classtype:trojan-activity; sid:100003712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2",nocase; classtype:trojan-activity; sid:100003713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3",nocase; classtype:trojan-activity; sid:100003714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karmakoincodes.weebly.com",nocase; http_uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe",nocase; classtype:trojan-activity; sid:100003715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kotakwarna.co.id",nocase; http_uri; content:"/dg/etrac/nf4emwz/",nocase; classtype:trojan-activity; sid:100003716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ksh.hu",nocase; http_uri; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe",nocase; classtype:trojan-activity; sid:100003717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kuaizip.com",nocase; http_uri; content:"/down/affiliate/kuaizip_setup_10029.exe",nocase; classtype:trojan-activity; sid:100003718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linuxforensicsbook.com.s3.amazonaws.com",nocase; http_uri; content:"/linuxforensicscode.zip",nocase; classtype:trojan-activity; sid:100003719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minpic.de",nocase; http_uri; content:"/k/big5/1giof6/",nocase; classtype:trojan-activity; sid:100003720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"my.cloudme.com",nocase; http_uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe",nocase; classtype:trojan-activity; sid:100003721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/aacenc.exe",nocase; classtype:trojan-activity; sid:100003722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/doxillionsetup.exe",nocase; classtype:trojan-activity; sid:100003723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newyarlfm.weebly.com",nocase; http_uri; content:"/uploads/4/1/6/6/4166984/keygen.exe",nocase; classtype:trojan-activity; sid:100003724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhipcauytevietnhat.com",nocase; http_uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/",nocase; classtype:trojan-activity; sid:100003725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"note.youdao.com",nocase; http_uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a",nocase; classtype:trojan-activity; sid:100003726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oldschoolvalue.s3.amazonaws.com",nocase; http_uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe",nocase; classtype:trojan-activity; sid:100003727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq",nocase; classtype:trojan-activity; sid:100003728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq",nocase; classtype:trojan-activity; sid:100003729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21108&authkey=acq44gahejhwrag",nocase; classtype:trojan-activity; sid:100003730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa",nocase; classtype:trojan-activity; sid:100003731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq",nocase; classtype:trojan-activity; sid:100003732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe",nocase; classtype:trojan-activity; sid:100003733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg",nocase; classtype:trojan-activity; sid:100003734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0",nocase; classtype:trojan-activity; sid:100003735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g",nocase; classtype:trojan-activity; sid:100003736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140",nocase; classtype:trojan-activity; sid:100003737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130",nocase; classtype:trojan-activity; sid:100003738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135",nocase; classtype:trojan-activity; sid:100003739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732",nocase; classtype:trojan-activity; sid:100003740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4",nocase; classtype:trojan-activity; sid:100003741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100003742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100003743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0",nocase; classtype:trojan-activity; sid:100003744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100003745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100003746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100003747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100003748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq",nocase; classtype:trojan-activity; sid:100003749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko",nocase; classtype:trojan-activity; sid:100003750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw",nocase; classtype:trojan-activity; sid:100003751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=032ce380af7ab389&resid=32ce380af7ab389!210&authkey=akcynbtc0h3ui7e",nocase; classtype:trojan-activity; sid:100003752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=032ce380af7ab389&resid=32ce380af7ab389%21210&authkey=akcynbtc0h3ui7e",nocase; classtype:trojan-activity; sid:100003753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma",nocase; classtype:trojan-activity; sid:100003754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48",nocase; classtype:trojan-activity; sid:100003755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq",nocase; classtype:trojan-activity; sid:100003756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg",nocase; classtype:trojan-activity; sid:100003757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw",nocase; classtype:trojan-activity; sid:100003758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq",nocase; classtype:trojan-activity; sid:100003759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d!184&authkey=ackbiiarirejcam",nocase; classtype:trojan-activity; sid:100003760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d%21184&authkey=ackbiiarirejcam",nocase; classtype:trojan-activity; sid:100003761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100003762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100003763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100003764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100003765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0!1667&authkey=an8otd7jzc7xgho",nocase; classtype:trojan-activity; sid:100003766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0%211667&authkey=an8otd7jzc7xgho",nocase; classtype:trojan-activity; sid:100003767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0da4ace18aa7d1e2&resid=da4ace18aa7d1e2%21131&authkey=adjn1y5pp4a10_c",nocase; classtype:trojan-activity; sid:100003768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100003769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100003770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw",nocase; classtype:trojan-activity; sid:100003771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0",nocase; classtype:trojan-activity; sid:100003772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a",nocase; classtype:trojan-activity; sid:100003773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4",nocase; classtype:trojan-activity; sid:100003774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo",nocase; classtype:trojan-activity; sid:100003775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100003776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100003777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f!286&authkey=almwisomhv3c0zc",nocase; classtype:trojan-activity; sid:100003778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc",nocase; classtype:trojan-activity; sid:100003779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100003780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100003781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100003782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100003783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100003784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100003785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve",nocase; classtype:trojan-activity; sid:100003786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w",nocase; classtype:trojan-activity; sid:100003787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100003788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg",nocase; classtype:trojan-activity; sid:100003789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60",nocase; classtype:trojan-activity; sid:100003790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg",nocase; classtype:trojan-activity; sid:100003791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4",nocase; classtype:trojan-activity; sid:100003792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c",nocase; classtype:trojan-activity; sid:100003793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c",nocase; classtype:trojan-activity; sid:100003794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!140&authkey=apn44x6bxlzq3ac",nocase; classtype:trojan-activity; sid:100003795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!151&authkey=aeuk7knodrpenek",nocase; classtype:trojan-activity; sid:100003796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!153&authkey=ao6e8g0bzbp_idw",nocase; classtype:trojan-activity; sid:100003797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!154&authkey=ah4chedbotzpmtq",nocase; classtype:trojan-activity; sid:100003798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!156&authkey=ajnqscnmrdonpkg",nocase; classtype:trojan-activity; sid:100003799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs",nocase; classtype:trojan-activity; sid:100003800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0",nocase; classtype:trojan-activity; sid:100003801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd",nocase; classtype:trojan-activity; sid:100003802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc",nocase; classtype:trojan-activity; sid:100003803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c",nocase; classtype:trojan-activity; sid:100003804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21140&authkey=apn44x6bxlzq3ac",nocase; classtype:trojan-activity; sid:100003805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21151&authkey=aeuk7knodrpenek",nocase; classtype:trojan-activity; sid:100003806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21153&authkey=ao6e8g0bzbp_idw",nocase; classtype:trojan-activity; sid:100003807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21154&authkey=ah4chedbotzpmtq",nocase; classtype:trojan-activity; sid:100003808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21156&authkey=ajnqscnmrdonpkg",nocase; classtype:trojan-activity; sid:100003809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po",nocase; classtype:trojan-activity; sid:100003810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe",nocase; classtype:trojan-activity; sid:100003811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk",nocase; classtype:trojan-activity; sid:100003812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100003813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100003814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu",nocase; classtype:trojan-activity; sid:100003815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k",nocase; classtype:trojan-activity; sid:100003816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo",nocase; classtype:trojan-activity; sid:100003817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk",nocase; classtype:trojan-activity; sid:100003818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei",nocase; classtype:trojan-activity; sid:100003819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte",nocase; classtype:trojan-activity; sid:100003820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk",nocase; classtype:trojan-activity; sid:100003821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei",nocase; classtype:trojan-activity; sid:100003822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte",nocase; classtype:trojan-activity; sid:100003823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga",nocase; classtype:trojan-activity; sid:100003824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2968c371f5450503&resid=2968c371f5450503!122&authkey=aaqhhxbnwfwrz28",nocase; classtype:trojan-activity; sid:100003825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2968c371f5450503&resid=2968c371f5450503%21122&authkey=aaqhhxbnwfwrz28",nocase; classtype:trojan-activity; sid:100003826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0",nocase; classtype:trojan-activity; sid:100003827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620",nocase; classtype:trojan-activity; sid:100003828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo",nocase; classtype:trojan-activity; sid:100003829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e",nocase; classtype:trojan-activity; sid:100003830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100003831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100003832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw",nocase; classtype:trojan-activity; sid:100003833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw",nocase; classtype:trojan-activity; sid:100003834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4",nocase; classtype:trojan-activity; sid:100003835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w",nocase; classtype:trojan-activity; sid:100003836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100003837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8",nocase; classtype:trojan-activity; sid:100003838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100003839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw",nocase; classtype:trojan-activity; sid:100003840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100003841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100003842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100003843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100003844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq",nocase; classtype:trojan-activity; sid:100003845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o",nocase; classtype:trojan-activity; sid:100003846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1!223&authkey=aajr842bzum0yg8",nocase; classtype:trojan-activity; sid:100003847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8",nocase; classtype:trojan-activity; sid:100003848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc",nocase; classtype:trojan-activity; sid:100003849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0",nocase; classtype:trojan-activity; sid:100003850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8",nocase; classtype:trojan-activity; sid:100003851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus",nocase; classtype:trojan-activity; sid:100003852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100003853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100003854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100003855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100003856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100003857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100003858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100003859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100003860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk",nocase; classtype:trojan-activity; sid:100003861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4",nocase; classtype:trojan-activity; sid:100003862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4",nocase; classtype:trojan-activity; sid:100003863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge",nocase; classtype:trojan-activity; sid:100003864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs",nocase; classtype:trojan-activity; sid:100003865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3ee68228c34c236d&resid=3ee68228c34c236d%21129&authkey=apll6hu3-xetzxu",nocase; classtype:trojan-activity; sid:100003866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100003867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100003868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100003869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100003870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba!2203&authkey=ajvalmr5l8epwvm",nocase; classtype:trojan-activity; sid:100003871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba%212203&authkey=ajvalmr5l8epwvm",nocase; classtype:trojan-activity; sid:100003872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100003873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100003874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik",nocase; classtype:trojan-activity; sid:100003875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq",nocase; classtype:trojan-activity; sid:100003876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy",nocase; classtype:trojan-activity; sid:100003877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21141&authkey=aazwaw2xjms24o0",nocase; classtype:trojan-activity; sid:100003878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100003879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100003880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y",nocase; classtype:trojan-activity; sid:100003881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100003882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100003883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100003884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100003885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y",nocase; classtype:trojan-activity; sid:100003886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo",nocase; classtype:trojan-activity; sid:100003887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4",nocase; classtype:trojan-activity; sid:100003888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm",nocase; classtype:trojan-activity; sid:100003889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu",nocase; classtype:trojan-activity; sid:100003890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100003891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100003892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc",nocase; classtype:trojan-activity; sid:100003893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y",nocase; classtype:trojan-activity; sid:100003894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8",nocase; classtype:trojan-activity; sid:100003895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0",nocase; classtype:trojan-activity; sid:100003896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc",nocase; classtype:trojan-activity; sid:100003897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs",nocase; classtype:trojan-activity; sid:100003898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts",nocase; classtype:trojan-activity; sid:100003899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc",nocase; classtype:trojan-activity; sid:100003900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg",nocase; classtype:trojan-activity; sid:100003901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y",nocase; classtype:trojan-activity; sid:100003902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday",nocase; classtype:trojan-activity; sid:100003903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0",nocase; classtype:trojan-activity; sid:100003904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas",nocase; classtype:trojan-activity; sid:100003905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy",nocase; classtype:trojan-activity; sid:100003906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14",nocase; classtype:trojan-activity; sid:100003907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i",nocase; classtype:trojan-activity; sid:100003908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu",nocase; classtype:trojan-activity; sid:100003909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c",nocase; classtype:trojan-activity; sid:100003910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy",nocase; classtype:trojan-activity; sid:100003911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q",nocase; classtype:trojan-activity; sid:100003912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm",nocase; classtype:trojan-activity; sid:100003913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4",nocase; classtype:trojan-activity; sid:100003914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho",nocase; classtype:trojan-activity; sid:100003915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18",nocase; classtype:trojan-activity; sid:100003916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q",nocase; classtype:trojan-activity; sid:100003917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm",nocase; classtype:trojan-activity; sid:100003918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na",nocase; classtype:trojan-activity; sid:100003919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk",nocase; classtype:trojan-activity; sid:100003920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe",nocase; classtype:trojan-activity; sid:100003921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi",nocase; classtype:trojan-activity; sid:100003922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc",nocase; classtype:trojan-activity; sid:100003923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc",nocase; classtype:trojan-activity; sid:100003924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100003925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100003926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100003927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100003928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100003929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100003930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100003931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100003932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100003933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100003934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100003935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4",nocase; classtype:trojan-activity; sid:100003936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu",nocase; classtype:trojan-activity; sid:100003937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8",nocase; classtype:trojan-activity; sid:100003938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8",nocase; classtype:trojan-activity; sid:100003939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100003940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100003941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8",nocase; classtype:trojan-activity; sid:100003942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100003943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100003944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100003945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g",nocase; classtype:trojan-activity; sid:100003946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum",nocase; classtype:trojan-activity; sid:100003947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi",nocase; classtype:trojan-activity; sid:100003948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy",nocase; classtype:trojan-activity; sid:100003949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o",nocase; classtype:trojan-activity; sid:100003950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa",nocase; classtype:trojan-activity; sid:100003951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100003952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100003953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc",nocase; classtype:trojan-activity; sid:100003954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk",nocase; classtype:trojan-activity; sid:100003955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea",nocase; classtype:trojan-activity; sid:100003956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100003957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100003958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100003959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100003960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100003961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100003962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo",nocase; classtype:trojan-activity; sid:100003963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva",nocase; classtype:trojan-activity; sid:100003964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles",nocase; classtype:trojan-activity; sid:100003965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg",nocase; classtype:trojan-activity; sid:100003966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100003967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100003968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100003969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100003970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw",nocase; classtype:trojan-activity; sid:100003971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8",nocase; classtype:trojan-activity; sid:100003972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq",nocase; classtype:trojan-activity; sid:100003973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug",nocase; classtype:trojan-activity; sid:100003974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua",nocase; classtype:trojan-activity; sid:100003975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe",nocase; classtype:trojan-activity; sid:100003976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i",nocase; classtype:trojan-activity; sid:100003977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa",nocase; classtype:trojan-activity; sid:100003978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe",nocase; classtype:trojan-activity; sid:100003979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m",nocase; classtype:trojan-activity; sid:100003980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi",nocase; classtype:trojan-activity; sid:100003981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21198&authkey=akq4jrbjm6spd9m",nocase; classtype:trojan-activity; sid:100003982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!109&authkey=ap-okubj9bvtlc0",nocase; classtype:trojan-activity; sid:100003983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21106&authkey=an9dhtmtufpis-m",nocase; classtype:trojan-activity; sid:100003984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21109&authkey=ap-okubj9bvtlc0",nocase; classtype:trojan-activity; sid:100003985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi",nocase; classtype:trojan-activity; sid:100003986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e",nocase; classtype:trojan-activity; sid:100003987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100003988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c",nocase; classtype:trojan-activity; sid:100003989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100003990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c",nocase; classtype:trojan-activity; sid:100003991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk",nocase; classtype:trojan-activity; sid:100003992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4",nocase; classtype:trojan-activity; sid:100003993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo",nocase; classtype:trojan-activity; sid:100003994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2!517&authkey=akfewcyiwlwomyk",nocase; classtype:trojan-activity; sid:100003995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji",nocase; classtype:trojan-activity; sid:100003996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21517&authkey=akfewcyiwlwomyk",nocase; classtype:trojan-activity; sid:100003997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100003998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100003999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg",nocase; classtype:trojan-activity; sid:100004000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70",nocase; classtype:trojan-activity; sid:100004001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc",nocase; classtype:trojan-activity; sid:100004002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100004003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100004004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100004005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100004006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw",nocase; classtype:trojan-activity; sid:100004007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq",nocase; classtype:trojan-activity; sid:100004008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm",nocase; classtype:trojan-activity; sid:100004009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100004010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100004011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8",nocase; classtype:trojan-activity; sid:100004012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100004013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100004014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!301&authkey=abquzhtdjg5pryk",nocase; classtype:trojan-activity; sid:100004015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!302&authkey=al2_xstzqulnnqw",nocase; classtype:trojan-activity; sid:100004016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!305&authkey=an-uuhplpk2zp5u",nocase; classtype:trojan-activity; sid:100004017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21301&authkey=abquzhtdjg5pryk",nocase; classtype:trojan-activity; sid:100004018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21302&authkey=al2_xstzqulnnqw",nocase; classtype:trojan-activity; sid:100004019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21305&authkey=an-uuhplpk2zp5u",nocase; classtype:trojan-activity; sid:100004020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu",nocase; classtype:trojan-activity; sid:100004021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i",nocase; classtype:trojan-activity; sid:100004022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70d8fa75c83fbdbe&resid=70d8fa75c83fbdbe%21144&authkey=acw8wl1noncfp-4",nocase; classtype:trojan-activity; sid:100004023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam",nocase; classtype:trojan-activity; sid:100004024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble",nocase; classtype:trojan-activity; sid:100004025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60",nocase; classtype:trojan-activity; sid:100004026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k",nocase; classtype:trojan-activity; sid:100004027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8",nocase; classtype:trojan-activity; sid:100004028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg",nocase; classtype:trojan-activity; sid:100004029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte",nocase; classtype:trojan-activity; sid:100004030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!106&authkey=ahu5s4ttjvxbnxo",nocase; classtype:trojan-activity; sid:100004031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!107&authkey=abj3eccentbeaqa",nocase; classtype:trojan-activity; sid:100004032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!108&authkey=amvcygo4prlgt4i",nocase; classtype:trojan-activity; sid:100004033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!110&authkey=ahzuehvk5nvzo90",nocase; classtype:trojan-activity; sid:100004034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21106&authkey=ahu5s4ttjvxbnxo",nocase; classtype:trojan-activity; sid:100004035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21107&authkey=abj3eccentbeaqa",nocase; classtype:trojan-activity; sid:100004036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21108&authkey=amvcygo4prlgt4i",nocase; classtype:trojan-activity; sid:100004037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21110&authkey=ahzuehvk5nvzo90",nocase; classtype:trojan-activity; sid:100004038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34",nocase; classtype:trojan-activity; sid:100004039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w",nocase; classtype:trojan-activity; sid:100004040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta",nocase; classtype:trojan-activity; sid:100004041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100004042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100004043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100004044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100004045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125570&authkey=aejqgjglwurnb0a",nocase; classtype:trojan-activity; sid:100004046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq",nocase; classtype:trojan-activity; sid:100004047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k",nocase; classtype:trojan-activity; sid:100004048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100004049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100004050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100004051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100004052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100004053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100004054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs",nocase; classtype:trojan-activity; sid:100004055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli",nocase; classtype:trojan-activity; sid:100004056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18",nocase; classtype:trojan-activity; sid:100004057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli",nocase; classtype:trojan-activity; sid:100004058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm",nocase; classtype:trojan-activity; sid:100004059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8",nocase; classtype:trojan-activity; sid:100004060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm",nocase; classtype:trojan-activity; sid:100004061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21444&authkey=abzxvycu0ggtmg8",nocase; classtype:trojan-activity; sid:100004062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c",nocase; classtype:trojan-activity; sid:100004063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0",nocase; classtype:trojan-activity; sid:100004064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq",nocase; classtype:trojan-activity; sid:100004065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda",nocase; classtype:trojan-activity; sid:100004066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm",nocase; classtype:trojan-activity; sid:100004067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk",nocase; classtype:trojan-activity; sid:100004068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4",nocase; classtype:trojan-activity; sid:100004069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c",nocase; classtype:trojan-activity; sid:100004070; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100004071; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100004072; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4",nocase; classtype:trojan-activity; sid:100004073; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=89360b4c7415c088&resid=89360b4c7415c088%21106&authkey=akfcfq3zq5oof2i",nocase; classtype:trojan-activity; sid:100004074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=89360b4c7415c088&resid=89360b4c7415c088%21108&authkey=amfbkmapqbvzpvk",nocase; classtype:trojan-activity; sid:100004075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk",nocase; classtype:trojan-activity; sid:100004076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk",nocase; classtype:trojan-activity; sid:100004077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae",nocase; classtype:trojan-activity; sid:100004078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0",nocase; classtype:trojan-activity; sid:100004079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8",nocase; classtype:trojan-activity; sid:100004080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!254&authkey=ajt5wxegbvzbwqa",nocase; classtype:trojan-activity; sid:100004081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!255&authkey=aaimhpp89qmcfhc",nocase; classtype:trojan-activity; sid:100004082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33%21254&authkey=ajt5wxegbvzbwqa",nocase; classtype:trojan-activity; sid:100004083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s",nocase; classtype:trojan-activity; sid:100004084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my",nocase; classtype:trojan-activity; sid:100004085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby",nocase; classtype:trojan-activity; sid:100004086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo",nocase; classtype:trojan-activity; sid:100004087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti",nocase; classtype:trojan-activity; sid:100004088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!112&authkey=af43qpcgl0t2f5o",nocase; classtype:trojan-activity; sid:100004089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8",nocase; classtype:trojan-activity; sid:100004090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o",nocase; classtype:trojan-activity; sid:100004091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8",nocase; classtype:trojan-activity; sid:100004092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe",nocase; classtype:trojan-activity; sid:100004093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari",nocase; classtype:trojan-activity; sid:100004094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4",nocase; classtype:trojan-activity; sid:100004095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia",nocase; classtype:trojan-activity; sid:100004096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok",nocase; classtype:trojan-activity; sid:100004097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!305&authkey=apgh_teb3673nek",nocase; classtype:trojan-activity; sid:100004098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!306&authkey=aibymhcuhqnmrwo",nocase; classtype:trojan-activity; sid:100004099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe",nocase; classtype:trojan-activity; sid:100004100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari",nocase; classtype:trojan-activity; sid:100004101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4",nocase; classtype:trojan-activity; sid:100004102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m",nocase; classtype:trojan-activity; sid:100004103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia",nocase; classtype:trojan-activity; sid:100004104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok",nocase; classtype:trojan-activity; sid:100004105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm",nocase; classtype:trojan-activity; sid:100004106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21305&authkey=apgh_teb3673nek",nocase; classtype:trojan-activity; sid:100004107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m",nocase; classtype:trojan-activity; sid:100004108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w",nocase; classtype:trojan-activity; sid:100004109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100004110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100004111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k",nocase; classtype:trojan-activity; sid:100004112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli",nocase; classtype:trojan-activity; sid:100004113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm",nocase; classtype:trojan-activity; sid:100004114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue",nocase; classtype:trojan-activity; sid:100004115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma",nocase; classtype:trojan-activity; sid:100004116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg",nocase; classtype:trojan-activity; sid:100004117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq",nocase; classtype:trojan-activity; sid:100004118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs",nocase; classtype:trojan-activity; sid:100004119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho",nocase; classtype:trojan-activity; sid:100004120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc",nocase; classtype:trojan-activity; sid:100004121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w",nocase; classtype:trojan-activity; sid:100004122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm",nocase; classtype:trojan-activity; sid:100004123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0",nocase; classtype:trojan-activity; sid:100004124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy",nocase; classtype:trojan-activity; sid:100004125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm",nocase; classtype:trojan-activity; sid:100004126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi",nocase; classtype:trojan-activity; sid:100004127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi",nocase; classtype:trojan-activity; sid:100004128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8",nocase; classtype:trojan-activity; sid:100004129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100004130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100004131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9fb622acb27482ef&resid=9fb622acb27482ef%211197&authkey=aeacibxy2zlyxro",nocase; classtype:trojan-activity; sid:100004132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o",nocase; classtype:trojan-activity; sid:100004133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4",nocase; classtype:trojan-activity; sid:100004134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi",nocase; classtype:trojan-activity; sid:100004135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100004136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100004137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo",nocase; classtype:trojan-activity; sid:100004138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq",nocase; classtype:trojan-activity; sid:100004139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a31988151cf6813e&resid=a31988151cf6813e%21107&authkey=ab9lanzt1aj_0ws",nocase; classtype:trojan-activity; sid:100004140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi",nocase; classtype:trojan-activity; sid:100004141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs",nocase; classtype:trojan-activity; sid:100004142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw",nocase; classtype:trojan-activity; sid:100004143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o",nocase; classtype:trojan-activity; sid:100004144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc",nocase; classtype:trojan-activity; sid:100004145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs",nocase; classtype:trojan-activity; sid:100004146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw",nocase; classtype:trojan-activity; sid:100004147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu",nocase; classtype:trojan-activity; sid:100004148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21256&authkey=aapnly5qifymcvw",nocase; classtype:trojan-activity; sid:100004149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100004150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100004151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi",nocase; classtype:trojan-activity; sid:100004152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc",nocase; classtype:trojan-activity; sid:100004153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy",nocase; classtype:trojan-activity; sid:100004154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc",nocase; classtype:trojan-activity; sid:100004155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey",nocase; classtype:trojan-activity; sid:100004156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg",nocase; classtype:trojan-activity; sid:100004157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui",nocase; classtype:trojan-activity; sid:100004158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi",nocase; classtype:trojan-activity; sid:100004159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818!129&authkey=aesewk3cf5vbrxw",nocase; classtype:trojan-activity; sid:100004160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818%21129&authkey=aesewk3cf5vbrxw",nocase; classtype:trojan-activity; sid:100004161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk",nocase; classtype:trojan-activity; sid:100004162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw",nocase; classtype:trojan-activity; sid:100004163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100004164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100004165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e",nocase; classtype:trojan-activity; sid:100004166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100004167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100004168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u",nocase; classtype:trojan-activity; sid:100004169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm",nocase; classtype:trojan-activity; sid:100004170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy",nocase; classtype:trojan-activity; sid:100004171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc",nocase; classtype:trojan-activity; sid:100004172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy",nocase; classtype:trojan-activity; sid:100004173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84",nocase; classtype:trojan-activity; sid:100004174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo",nocase; classtype:trojan-activity; sid:100004175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw",nocase; classtype:trojan-activity; sid:100004176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww",nocase; classtype:trojan-activity; sid:100004177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy",nocase; classtype:trojan-activity; sid:100004178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w",nocase; classtype:trojan-activity; sid:100004179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq",nocase; classtype:trojan-activity; sid:100004180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100004181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100004182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg",nocase; classtype:trojan-activity; sid:100004183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg",nocase; classtype:trojan-activity; sid:100004184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100004185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100004186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m",nocase; classtype:trojan-activity; sid:100004187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8",nocase; classtype:trojan-activity; sid:100004188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1047&authkey=aod6jbxyicq2v4g",nocase; classtype:trojan-activity; sid:100004189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211047&authkey=aod6jbxyicq2v4g",nocase; classtype:trojan-activity; sid:100004190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100004191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100004192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq",nocase; classtype:trojan-activity; sid:100004193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm",nocase; classtype:trojan-activity; sid:100004194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai",nocase; classtype:trojan-activity; sid:100004195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk",nocase; classtype:trojan-activity; sid:100004196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100004197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100004198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100004199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100004200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100004201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100004202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100004203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100004204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100004205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100004206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100004207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100004208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100004209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100004210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100004211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100004212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100004213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100004214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100004215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100004216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8",nocase; classtype:trojan-activity; sid:100004217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc",nocase; classtype:trojan-activity; sid:100004218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc",nocase; classtype:trojan-activity; sid:100004219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs",nocase; classtype:trojan-activity; sid:100004220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m",nocase; classtype:trojan-activity; sid:100004221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga",nocase; classtype:trojan-activity; sid:100004222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk",nocase; classtype:trojan-activity; sid:100004223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!362&authkey=alycl9izrvfl7oc",nocase; classtype:trojan-activity; sid:100004224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21362&authkey=alycl9izrvfl7oc",nocase; classtype:trojan-activity; sid:100004225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg",nocase; classtype:trojan-activity; sid:100004226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100004227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100004228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw",nocase; classtype:trojan-activity; sid:100004229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cda6c13b54bbe48c&resid=cda6c13b54bbe48c!44331&authkey=afohia-wo-alwiy",nocase; classtype:trojan-activity; sid:100004230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cda6c13b54bbe48c&resid=cda6c13b54bbe48c%2144331&authkey=afohia-wo-alwiy",nocase; classtype:trojan-activity; sid:100004231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100004232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100004233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100004234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100004235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100004236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100004237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100004238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100004239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100004240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100004241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0",nocase; classtype:trojan-activity; sid:100004242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d4d413b6e7cf7088&resid=d4d413b6e7cf7088%211271&authkey=akz65bxpgvdxjb8",nocase; classtype:trojan-activity; sid:100004243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100004244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100004245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100004246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100004247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy",nocase; classtype:trojan-activity; sid:100004248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe",nocase; classtype:trojan-activity; sid:100004249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq",nocase; classtype:trojan-activity; sid:100004250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4",nocase; classtype:trojan-activity; sid:100004251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq",nocase; classtype:trojan-activity; sid:100004252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100004253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100004254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100004255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100004256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100004257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100004258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2!1818&authkey=anh2wga7qmhbmuo",nocase; classtype:trojan-activity; sid:100004259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2%211818&authkey=anh2wga7qmhbmuo",nocase; classtype:trojan-activity; sid:100004260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw",nocase; classtype:trojan-activity; sid:100004261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0",nocase; classtype:trojan-activity; sid:100004262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4",nocase; classtype:trojan-activity; sid:100004263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs",nocase; classtype:trojan-activity; sid:100004264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0",nocase; classtype:trojan-activity; sid:100004265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q",nocase; classtype:trojan-activity; sid:100004266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2!107&authkey=af-bicrg1c6vgck",nocase; classtype:trojan-activity; sid:100004267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2%21107&authkey=af-bicrg1c6vgck",nocase; classtype:trojan-activity; sid:100004268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co",nocase; classtype:trojan-activity; sid:100004269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co",nocase; classtype:trojan-activity; sid:100004270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc",nocase; classtype:trojan-activity; sid:100004271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc",nocase; classtype:trojan-activity; sid:100004272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0",nocase; classtype:trojan-activity; sid:100004273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c",nocase; classtype:trojan-activity; sid:100004274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg",nocase; classtype:trojan-activity; sid:100004275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100004276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100004277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq",nocase; classtype:trojan-activity; sid:100004278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e627fc797baa3032&resid=e627fc797baa3032%212324&authkey=aa8i-r7ixmcraha",nocase; classtype:trojan-activity; sid:100004279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke",nocase; classtype:trojan-activity; sid:100004280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom",nocase; classtype:trojan-activity; sid:100004281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da",nocase; classtype:trojan-activity; sid:100004282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100004283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100004284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8!148&authkey=agjcwq650c8wdbm",nocase; classtype:trojan-activity; sid:100004285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8!150&authkey=ami5aqoinvosjle",nocase; classtype:trojan-activity; sid:100004286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8%21148&authkey=agjcwq650c8wdbm",nocase; classtype:trojan-activity; sid:100004287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8%21150&authkey=ami5aqoinvosjle",nocase; classtype:trojan-activity; sid:100004288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0",nocase; classtype:trojan-activity; sid:100004289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100004290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100004291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai",nocase; classtype:trojan-activity; sid:100004292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc",nocase; classtype:trojan-activity; sid:100004293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8",nocase; classtype:trojan-activity; sid:100004294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns",nocase; classtype:trojan-activity; sid:100004295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8",nocase; classtype:trojan-activity; sid:100004296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ef7cc06ce7ffafb8&resid=ef7cc06ce7ffafb8%21108&authkey=anmpeqm9gm_zv9m",nocase; classtype:trojan-activity; sid:100004297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100004298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100004299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100004300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100004301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100004302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100004303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0",nocase; classtype:trojan-activity; sid:100004304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw",nocase; classtype:trojan-activity; sid:100004305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e",nocase; classtype:trojan-activity; sid:100004306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu",nocase; classtype:trojan-activity; sid:100004307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq",nocase; classtype:trojan-activity; sid:100004308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k",nocase; classtype:trojan-activity; sid:100004309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie",nocase; classtype:trojan-activity; sid:100004310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c",nocase; classtype:trojan-activity; sid:100004311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g",nocase; classtype:trojan-activity; sid:100004312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta",nocase; classtype:trojan-activity; sid:100004313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o",nocase; classtype:trojan-activity; sid:100004314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao",nocase; classtype:trojan-activity; sid:100004315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!226&authkey=adho6klfkjflaqk",nocase; classtype:trojan-activity; sid:100004316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!229&authkey=akvo12quxgcwnk8",nocase; classtype:trojan-activity; sid:100004317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!234&authkey=abhyu_zfy6bhwmu",nocase; classtype:trojan-activity; sid:100004318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o",nocase; classtype:trojan-activity; sid:100004319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21226&authkey=adho6klfkjflaqk",nocase; classtype:trojan-activity; sid:100004320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21234&authkey=abhyu_zfy6bhwmu",nocase; classtype:trojan-activity; sid:100004321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c!115&authkey=adbcrakskolznjq",nocase; classtype:trojan-activity; sid:100004322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c%21115&authkey=adbcrakskolznjq",nocase; classtype:trojan-activity; sid:100004323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c%21116&authkey=anenotuhbsni0zu",nocase; classtype:trojan-activity; sid:100004324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22",nocase; classtype:trojan-activity; sid:100004325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100004326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100004327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100004328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100004329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc",nocase; classtype:trojan-activity; sid:100004330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu",nocase; classtype:trojan-activity; sid:100004331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm",nocase; classtype:trojan-activity; sid:100004332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w",nocase; classtype:trojan-activity; sid:100004333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm",nocase; classtype:trojan-activity; sid:100004334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21848&authkey=ag1_e421v-t5r9w",nocase; classtype:trojan-activity; sid:100004335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw",nocase; classtype:trojan-activity; sid:100004336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!198&authkey=amg468jpljbyyky",nocase; classtype:trojan-activity; sid:100004337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21198&authkey=amg468jpljbyyky",nocase; classtype:trojan-activity; sid:100004338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100004339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100004340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100004341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100004342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100004343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100004344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg",nocase; classtype:trojan-activity; sid:100004345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100004346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm",nocase; classtype:trojan-activity; sid:100004347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100004348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paste.ee",nocase; http_uri; content:"/r/a39ev",nocase; classtype:trojan-activity; sid:100004349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paste.ee",nocase; http_uri; content:"/r/oitkz",nocase; classtype:trojan-activity; sid:100004350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/77jhk0iw",nocase; classtype:trojan-activity; sid:100004351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/89hkc7wb",nocase; classtype:trojan-activity; sid:100004352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/yqvsvlvq",nocase; classtype:trojan-activity; sid:100004353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pierreconsulting.info",nocase; http_uri; content:"/wp-admin/llc/mwcacs65xienqdp/",nocase; classtype:trojan-activity; sid:100004354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pioneiraagronegocio.com.br",nocase; http_uri; content:"/bayesian-forecasting-amj5e/s5hqmf6/",nocase; classtype:trojan-activity; sid:100004355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skoda22.jpg",nocase; classtype:trojan-activity; sid:100004356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg",nocase; classtype:trojan-activity; sid:100004357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qjbutterflyevents.co.za",nocase; http_uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/",nocase; classtype:trojan-activity; sid:100004358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/dhlshipmentawb80326979402.ace",nocase; classtype:trojan-activity; sid:100004359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/maersk-bl+draft-copy-shipping-documents.ace",nocase; classtype:trojan-activity; sid:100004360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/po+for+april+shipment.ace",nocase; classtype:trojan-activity; sid:100004361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"racisa.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/zenar.exe",nocase; classtype:trojan-activity; sid:100004362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll",nocase; classtype:trojan-activity; sid:100004363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe",nocase; classtype:trojan-activity; sid:100004364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe",nocase; classtype:trojan-activity; sid:100004365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe",nocase; classtype:trojan-activity; sid:100004366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe",nocase; classtype:trojan-activity; sid:100004367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar",nocase; classtype:trojan-activity; sid:100004368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/myqseeaccount/one/main/one.htm",nocase; classtype:trojan-activity; sid:100004369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp",nocase; classtype:trojan-activity; sid:100004370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe",nocase; classtype:trojan-activity; sid:100004371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe",nocase; classtype:trojan-activity; sid:100004372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/tennc/webshell/master/other/small_shell.txt",nocase; classtype:trojan-activity; sid:100004373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.yeshen.com",nocase; http_uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe",nocase; classtype:trojan-activity; sid:100004374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sendspace.com",nocase; http_uri; content:"/pro/dl/q05z91",nocase; classtype:trojan-activity; sid:100004375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shribharatvatika.com",nocase; http_uri; content:"/ey4lpx8rx.zip",nocase; classtype:trojan-activity; sid:100004376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sites.google.com",nocase; http_uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0",nocase; classtype:trojan-activity; sid:100004377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt",nocase; classtype:trojan-activity; sid:100004378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt",nocase; classtype:trojan-activity; sid:100004379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt",nocase; classtype:trojan-activity; sid:100004380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt",nocase; classtype:trojan-activity; sid:100004381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt",nocase; classtype:trojan-activity; sid:100004382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt",nocase; classtype:trojan-activity; sid:100004383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg",nocase; classtype:trojan-activity; sid:100004384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt",nocase; classtype:trojan-activity; sid:100004385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt",nocase; classtype:trojan-activity; sid:100004386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technologydistilled.com",nocase; http_uri; content:"/a-nurse-ss8d9/z/",nocase; classtype:trojan-activity; sid:100004387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsrv4.ws",nocase; http_uri; content:"/23.exe",nocase; classtype:trojan-activity; sid:100004388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"users.skynet.be",nocase; http_uri; content:"/crisanar/defis/jek_crackme1.7.zip",nocase; classtype:trojan-activity; sid:100004389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/amowvegfrt9ja/",nocase; classtype:trojan-activity; sid:100004390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/",nocase; classtype:trojan-activity; sid:100004391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100004392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100004393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe",nocase; classtype:trojan-activity; sid:100004394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb%5efr_ouverture.exe",nocase; classtype:trojan-activity; sid:100004395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb^fr_ouverture.exe",nocase; classtype:trojan-activity; sid:100004396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe",nocase; classtype:trojan-activity; sid:100004397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/151_155/tidex_-_short_stuff.exe",nocase; classtype:trojan-activity; sid:100004398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikileaks.org",nocase; http_uri; content:"/syria-files/attach/222/222051_instruction.zip",nocase; classtype:trojan-activity; sid:100004399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.223.92",nocase; classtype:trojan-activity; sid:100000160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.225.24",nocase; classtype:trojan-activity; sid:100000161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.235.57",nocase; classtype:trojan-activity; sid:100000162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.249.21",nocase; classtype:trojan-activity; sid:100000163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.4.2",nocase; classtype:trojan-activity; sid:100000164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110fss.net",nocase; classtype:trojan-activity; sid:100000165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.41.173",nocase; classtype:trojan-activity; sid:100000166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.88.61",nocase; classtype:trojan-activity; sid:100000167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.119.245.114",nocase; classtype:trojan-activity; sid:100000168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.125.67.125",nocase; classtype:trojan-activity; sid:100000169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.165.21.195",nocase; classtype:trojan-activity; sid:100000170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.166.236.191",nocase; classtype:trojan-activity; sid:100000171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.167.151.156",nocase; classtype:trojan-activity; sid:100000172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.85.71",nocase; classtype:trojan-activity; sid:100000173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.86.31",nocase; classtype:trojan-activity; sid:100000174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.172.57.20",nocase; classtype:trojan-activity; sid:100000175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.182.235.252",nocase; classtype:trojan-activity; sid:100000176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.171.111",nocase; classtype:trojan-activity; sid:100000177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.177.85",nocase; classtype:trojan-activity; sid:100000178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.23.84",nocase; classtype:trojan-activity; sid:100000179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.230.136",nocase; classtype:trojan-activity; sid:100000180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.27.9",nocase; classtype:trojan-activity; sid:100000181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.49.223",nocase; classtype:trojan-activity; sid:100000182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.122",nocase; classtype:trojan-activity; sid:100000183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.66",nocase; classtype:trojan-activity; sid:100000184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.104.141",nocase; classtype:trojan-activity; sid:100000185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.104.15",nocase; classtype:trojan-activity; sid:100000186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.19",nocase; classtype:trojan-activity; sid:100000187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.222",nocase; classtype:trojan-activity; sid:100000188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.223",nocase; classtype:trojan-activity; sid:100000189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.226",nocase; classtype:trojan-activity; sid:100000190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.228",nocase; classtype:trojan-activity; sid:100000191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.26.243",nocase; classtype:trojan-activity; sid:100000192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.8.81",nocase; classtype:trojan-activity; sid:100000193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.61.52.53",nocase; classtype:trojan-activity; sid:100000194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.108.184",nocase; classtype:trojan-activity; sid:100000195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.133.222.151",nocase; classtype:trojan-activity; sid:100000196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.147.92.51",nocase; classtype:trojan-activity; sid:100000197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.159.108.96",nocase; classtype:trojan-activity; sid:100000198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.163.200.217",nocase; classtype:trojan-activity; sid:100000199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.124.75",nocase; classtype:trojan-activity; sid:100000200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.210.211",nocase; classtype:trojan-activity; sid:100000201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.96.252",nocase; classtype:trojan-activity; sid:100000202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.187.91.117",nocase; classtype:trojan-activity; sid:100000203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.214.127.42",nocase; classtype:trojan-activity; sid:100000204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.187.19",nocase; classtype:trojan-activity; sid:100000205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.236.77",nocase; classtype:trojan-activity; sid:100000206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.239.126",nocase; classtype:trojan-activity; sid:100000207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.43.27",nocase; classtype:trojan-activity; sid:100000208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.118.229",nocase; classtype:trojan-activity; sid:100000209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.202.111",nocase; classtype:trojan-activity; sid:100000210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.67.193",nocase; classtype:trojan-activity; sid:100000211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.180.95",nocase; classtype:trojan-activity; sid:100000212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.79.114",nocase; classtype:trojan-activity; sid:100000213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.79.137",nocase; classtype:trojan-activity; sid:100000214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.178.109",nocase; classtype:trojan-activity; sid:100000215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.188.28",nocase; classtype:trojan-activity; sid:100000216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.230.168.103",nocase; classtype:trojan-activity; sid:100000217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.218.202",nocase; classtype:trojan-activity; sid:100000218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.235.149.73",nocase; classtype:trojan-activity; sid:100000219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.235.188.86",nocase; classtype:trojan-activity; sid:100000220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.171.69",nocase; classtype:trojan-activity; sid:100000221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.141.241",nocase; classtype:trojan-activity; sid:100000222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.144.226",nocase; classtype:trojan-activity; sid:100000223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.197.144",nocase; classtype:trojan-activity; sid:100000224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.209.30",nocase; classtype:trojan-activity; sid:100000225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.75.157",nocase; classtype:trojan-activity; sid:100000226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.143.135",nocase; classtype:trojan-activity; sid:100000227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.17.120",nocase; classtype:trojan-activity; sid:100000228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.190.207",nocase; classtype:trojan-activity; sid:100000229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.227.228",nocase; classtype:trojan-activity; sid:100000230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.39.2",nocase; classtype:trojan-activity; sid:100000231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.73.181",nocase; classtype:trojan-activity; sid:100000232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.240.216.17",nocase; classtype:trojan-activity; sid:100000233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.152.44",nocase; classtype:trojan-activity; sid:100000234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.2.247",nocase; classtype:trojan-activity; sid:100000235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.243.80",nocase; classtype:trojan-activity; sid:100000236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.12.89",nocase; classtype:trojan-activity; sid:100000237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.8.24",nocase; classtype:trojan-activity; sid:100000238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.126.58",nocase; classtype:trojan-activity; sid:100000239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.162.50",nocase; classtype:trojan-activity; sid:100000240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.180.49",nocase; classtype:trojan-activity; sid:100000241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.51.77",nocase; classtype:trojan-activity; sid:100000242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.100.14",nocase; classtype:trojan-activity; sid:100000243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.121.39",nocase; classtype:trojan-activity; sid:100000244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.16.222",nocase; classtype:trojan-activity; sid:100000245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.191.118",nocase; classtype:trojan-activity; sid:100000246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.214.146",nocase; classtype:trojan-activity; sid:100000247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.240.226",nocase; classtype:trojan-activity; sid:100000248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.25.42",nocase; classtype:trojan-activity; sid:100000249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.8.112",nocase; classtype:trojan-activity; sid:100000250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.81.173",nocase; classtype:trojan-activity; sid:100000251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.82.122",nocase; classtype:trojan-activity; sid:100000252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.148.90",nocase; classtype:trojan-activity; sid:100000253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.197.164",nocase; classtype:trojan-activity; sid:100000254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.109.217",nocase; classtype:trojan-activity; sid:100000255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.118.157",nocase; classtype:trojan-activity; sid:100000256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.26.129",nocase; classtype:trojan-activity; sid:100000257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.79.98",nocase; classtype:trojan-activity; sid:100000258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.250.102.173",nocase; classtype:trojan-activity; sid:100000259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.218.210",nocase; classtype:trojan-activity; sid:100000260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.136.84",nocase; classtype:trojan-activity; sid:100000261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.196.17",nocase; classtype:trojan-activity; sid:100000262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.221.244",nocase; classtype:trojan-activity; sid:100000263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.239.103",nocase; classtype:trojan-activity; sid:100000264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.254.208.123",nocase; classtype:trojan-activity; sid:100000265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.254.32.5",nocase; classtype:trojan-activity; sid:100000266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.38.10",nocase; classtype:trojan-activity; sid:100000267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.6.129",nocase; classtype:trojan-activity; sid:100000268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.8.235",nocase; classtype:trojan-activity; sid:100000269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.121.163",nocase; classtype:trojan-activity; sid:100000270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.108",nocase; classtype:trojan-activity; sid:100000271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.111",nocase; classtype:trojan-activity; sid:100000272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.117",nocase; classtype:trojan-activity; sid:100000273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.122",nocase; classtype:trojan-activity; sid:100000274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.124",nocase; classtype:trojan-activity; sid:100000275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.131",nocase; classtype:trojan-activity; sid:100000276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.132",nocase; classtype:trojan-activity; sid:100000277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.133",nocase; classtype:trojan-activity; sid:100000278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.138",nocase; classtype:trojan-activity; sid:100000279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.139",nocase; classtype:trojan-activity; sid:100000280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.142",nocase; classtype:trojan-activity; sid:100000281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.143",nocase; classtype:trojan-activity; sid:100000282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.146",nocase; classtype:trojan-activity; sid:100000283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.149",nocase; classtype:trojan-activity; sid:100000284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.150",nocase; classtype:trojan-activity; sid:100000285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.151",nocase; classtype:trojan-activity; sid:100000286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.158",nocase; classtype:trojan-activity; sid:100000287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.160",nocase; classtype:trojan-activity; sid:100000288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.162",nocase; classtype:trojan-activity; sid:100000289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.163",nocase; classtype:trojan-activity; sid:100000290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.165",nocase; classtype:trojan-activity; sid:100000291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.171",nocase; classtype:trojan-activity; sid:100000292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.174",nocase; classtype:trojan-activity; sid:100000293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.175",nocase; classtype:trojan-activity; sid:100000294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.177",nocase; classtype:trojan-activity; sid:100000295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.178",nocase; classtype:trojan-activity; sid:100000296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.179",nocase; classtype:trojan-activity; sid:100000297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.127.155",nocase; classtype:trojan-activity; sid:100000298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.182",nocase; classtype:trojan-activity; sid:100000299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.23",nocase; classtype:trojan-activity; sid:100000300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.85.113",nocase; classtype:trojan-activity; sid:100000301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.87.213",nocase; classtype:trojan-activity; sid:100000302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.88.116",nocase; classtype:trojan-activity; sid:100000303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.91.212",nocase; classtype:trojan-activity; sid:100000304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.133",nocase; classtype:trojan-activity; sid:100000305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.158",nocase; classtype:trojan-activity; sid:100000306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.164",nocase; classtype:trojan-activity; sid:100000307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.168",nocase; classtype:trojan-activity; sid:100000308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.177",nocase; classtype:trojan-activity; sid:100000309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.188",nocase; classtype:trojan-activity; sid:100000310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.190",nocase; classtype:trojan-activity; sid:100000311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.211",nocase; classtype:trojan-activity; sid:100000312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.219",nocase; classtype:trojan-activity; sid:100000313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.229",nocase; classtype:trojan-activity; sid:100000314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.230",nocase; classtype:trojan-activity; sid:100000315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.247",nocase; classtype:trojan-activity; sid:100000316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.57",nocase; classtype:trojan-activity; sid:100000317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.90",nocase; classtype:trojan-activity; sid:100000318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.91",nocase; classtype:trojan-activity; sid:100000319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.31",nocase; classtype:trojan-activity; sid:100000320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.36",nocase; classtype:trojan-activity; sid:100000321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.38",nocase; classtype:trojan-activity; sid:100000322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.41",nocase; classtype:trojan-activity; sid:100000323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.43",nocase; classtype:trojan-activity; sid:100000324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.48",nocase; classtype:trojan-activity; sid:100000325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.52",nocase; classtype:trojan-activity; sid:100000326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.35.237",nocase; classtype:trojan-activity; sid:100000327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.38.98",nocase; classtype:trojan-activity; sid:100000328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.103",nocase; classtype:trojan-activity; sid:100000329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.118",nocase; classtype:trojan-activity; sid:100000330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.121",nocase; classtype:trojan-activity; sid:100000331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.124",nocase; classtype:trojan-activity; sid:100000332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.136",nocase; classtype:trojan-activity; sid:100000333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.52",nocase; classtype:trojan-activity; sid:100000334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.240.239",nocase; classtype:trojan-activity; sid:100000335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.87.98",nocase; classtype:trojan-activity; sid:100000336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.224.79",nocase; classtype:trojan-activity; sid:100000337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.65.53.175",nocase; classtype:trojan-activity; sid:100000338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.153.37",nocase; classtype:trojan-activity; sid:100000339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.159",nocase; classtype:trojan-activity; sid:100000340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.49",nocase; classtype:trojan-activity; sid:100000341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.53",nocase; classtype:trojan-activity; sid:100000342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.112",nocase; classtype:trojan-activity; sid:100000343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.84",nocase; classtype:trojan-activity; sid:100000344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.226.202",nocase; classtype:trojan-activity; sid:100000345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.78.45.158",nocase; classtype:trojan-activity; sid:100000346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.117.32",nocase; classtype:trojan-activity; sid:100000347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.118.16",nocase; classtype:trojan-activity; sid:100000348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.127.91",nocase; classtype:trojan-activity; sid:100000349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.207.144",nocase; classtype:trojan-activity; sid:100000350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.215.101",nocase; classtype:trojan-activity; sid:100000351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.218.56",nocase; classtype:trojan-activity; sid:100000352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.146.253",nocase; classtype:trojan-activity; sid:100000353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.18.255",nocase; classtype:trojan-activity; sid:100000354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.224.139",nocase; classtype:trojan-activity; sid:100000355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.93.29.211",nocase; classtype:trojan-activity; sid:100000356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.11.95.254",nocase; classtype:trojan-activity; sid:100000357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.144.140",nocase; classtype:trojan-activity; sid:100000358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.122.238.68",nocase; classtype:trojan-activity; sid:100000359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.161.58.249",nocase; classtype:trojan-activity; sid:100000360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.161.78.185",nocase; classtype:trojan-activity; sid:100000361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.172.250.35",nocase; classtype:trojan-activity; sid:100000362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.195.163.26",nocase; classtype:trojan-activity; sid:100000363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.226.42.250",nocase; classtype:trojan-activity; sid:100000364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.194.172",nocase; classtype:trojan-activity; sid:100000365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.35.229",nocase; classtype:trojan-activity; sid:100000366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.211.131",nocase; classtype:trojan-activity; sid:100000367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.254.169.251",nocase; classtype:trojan-activity; sid:100000368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.128.133",nocase; classtype:trojan-activity; sid:100000369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.133.16",nocase; classtype:trojan-activity; sid:100000370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.154.21",nocase; classtype:trojan-activity; sid:100000371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.191.47",nocase; classtype:trojan-activity; sid:100000372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.61.204.205",nocase; classtype:trojan-activity; sid:100000373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.89.43.185",nocase; classtype:trojan-activity; sid:100000374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.90.26.136",nocase; classtype:trojan-activity; sid:100000375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.111.242.3",nocase; classtype:trojan-activity; sid:100000376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.199.253.235",nocase; classtype:trojan-activity; sid:100000377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.200.154.181",nocase; classtype:trojan-activity; sid:100000378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.224.203.128",nocase; classtype:trojan-activity; sid:100000379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.226.100.56",nocase; classtype:trojan-activity; sid:100000380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.228.205.101",nocase; classtype:trojan-activity; sid:100000381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.229.165.194",nocase; classtype:trojan-activity; sid:100000382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.235.115.236",nocase; classtype:trojan-activity; sid:100000383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.30.54.64",nocase; classtype:trojan-activity; sid:100000384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.79.172.42",nocase; classtype:trojan-activity; sid:100000385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.165.216.112",nocase; classtype:trojan-activity; sid:100000386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.201.38.185",nocase; classtype:trojan-activity; sid:100000387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.42.47.36",nocase; classtype:trojan-activity; sid:100000388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.21.56",nocase; classtype:trojan-activity; sid:100000389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.125.55",nocase; classtype:trojan-activity; sid:100000390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.18.65",nocase; classtype:trojan-activity; sid:100000391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.153.194",nocase; classtype:trojan-activity; sid:100000392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.60.129",nocase; classtype:trojan-activity; sid:100000393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.131.242",nocase; classtype:trojan-activity; sid:100000394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.133.96",nocase; classtype:trojan-activity; sid:100000395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.144.213",nocase; classtype:trojan-activity; sid:100000396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.159.132",nocase; classtype:trojan-activity; sid:100000397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.132.140",nocase; classtype:trojan-activity; sid:100000398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.165.147",nocase; classtype:trojan-activity; sid:100000399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.255.194",nocase; classtype:trojan-activity; sid:100000400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.118.201",nocase; classtype:trojan-activity; sid:100000401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.69.102.84",nocase; classtype:trojan-activity; sid:100000402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.73.3.11",nocase; classtype:trojan-activity; sid:100000403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.92.174.231",nocase; classtype:trojan-activity; sid:100000404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.124.219.2",nocase; classtype:trojan-activity; sid:100000405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.132.151.60",nocase; classtype:trojan-activity; sid:100000406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.206.164.46",nocase; classtype:trojan-activity; sid:100000407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.211.100.26",nocase; classtype:trojan-activity; sid:100000408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.212.132.119",nocase; classtype:trojan-activity; sid:100000409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.212.142.215",nocase; classtype:trojan-activity; sid:100000410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.166.219",nocase; classtype:trojan-activity; sid:100000411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.196.50.107",nocase; classtype:trojan-activity; sid:100000412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.138",nocase; classtype:trojan-activity; sid:100000413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.5",nocase; classtype:trojan-activity; sid:100000414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.210.52",nocase; classtype:trojan-activity; sid:100000415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.220.126",nocase; classtype:trojan-activity; sid:100000416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.236.14",nocase; classtype:trojan-activity; sid:100000417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.243.40",nocase; classtype:trojan-activity; sid:100000418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.247.150",nocase; classtype:trojan-activity; sid:100000419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.200.76.54",nocase; classtype:trojan-activity; sid:100000420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.66.15",nocase; classtype:trojan-activity; sid:100000421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.69.113",nocase; classtype:trojan-activity; sid:100000422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.10.108",nocase; classtype:trojan-activity; sid:100000423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.15.72",nocase; classtype:trojan-activity; sid:100000424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.248.63.12",nocase; classtype:trojan-activity; sid:100000425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.113.146",nocase; classtype:trojan-activity; sid:100000426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.195.140",nocase; classtype:trojan-activity; sid:100000427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.53.15",nocase; classtype:trojan-activity; sid:100000428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.86.105.110",nocase; classtype:trojan-activity; sid:100000429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.104.35",nocase; classtype:trojan-activity; sid:100000430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.157.64",nocase; classtype:trojan-activity; sid:100000431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.7.132",nocase; classtype:trojan-activity; sid:100000432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.32.74",nocase; classtype:trojan-activity; sid:100000433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.5.149",nocase; classtype:trojan-activity; sid:100000434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.72.141",nocase; classtype:trojan-activity; sid:100000435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.12.130",nocase; classtype:trojan-activity; sid:100000436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.128.147",nocase; classtype:trojan-activity; sid:100000437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.208.215",nocase; classtype:trojan-activity; sid:100000438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.209.108",nocase; classtype:trojan-activity; sid:100000439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.214.72",nocase; classtype:trojan-activity; sid:100000440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.88.146",nocase; classtype:trojan-activity; sid:100000441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.150",nocase; classtype:trojan-activity; sid:100000442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.6",nocase; classtype:trojan-activity; sid:100000443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.221.162",nocase; classtype:trojan-activity; sid:100000444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.63.194",nocase; classtype:trojan-activity; sid:100000445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.65.93",nocase; classtype:trojan-activity; sid:100000446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.42.125.246",nocase; classtype:trojan-activity; sid:100000447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.43.180.33",nocase; classtype:trojan-activity; sid:100000448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.125.92",nocase; classtype:trojan-activity; sid:100000449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.50.203",nocase; classtype:trojan-activity; sid:100000450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.58.82",nocase; classtype:trojan-activity; sid:100000451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.83.79.43",nocase; classtype:trojan-activity; sid:100000452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.91.24.27",nocase; classtype:trojan-activity; sid:100000453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.91.41.135",nocase; classtype:trojan-activity; sid:100000454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.179.164",nocase; classtype:trojan-activity; sid:100000455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.183.235",nocase; classtype:trojan-activity; sid:100000456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.239.217",nocase; classtype:trojan-activity; sid:100000457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.108.161.25",nocase; classtype:trojan-activity; sid:100000458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.112.185.232",nocase; classtype:trojan-activity; sid:100000459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.119.63.145",nocase; classtype:trojan-activity; sid:100000460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.14.143.145",nocase; classtype:trojan-activity; sid:100000461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.147.213.57",nocase; classtype:trojan-activity; sid:100000462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.163.93.191",nocase; classtype:trojan-activity; sid:100000463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.18.235",nocase; classtype:trojan-activity; sid:100000464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.107.93",nocase; classtype:trojan-activity; sid:100000465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.163.220",nocase; classtype:trojan-activity; sid:100000466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.174.63",nocase; classtype:trojan-activity; sid:100000467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.197.106",nocase; classtype:trojan-activity; sid:100000468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.241.222",nocase; classtype:trojan-activity; sid:100000469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.27.77",nocase; classtype:trojan-activity; sid:100000470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.68.145",nocase; classtype:trojan-activity; sid:100000471; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.170.241",nocase; classtype:trojan-activity; sid:100000472; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.97.6",nocase; classtype:trojan-activity; sid:100000473; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.26.33",nocase; classtype:trojan-activity; sid:100000474; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.177.147.38",nocase; classtype:trojan-activity; sid:100000475; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.248.123",nocase; classtype:trojan-activity; sid:100000476; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.170.212",nocase; classtype:trojan-activity; sid:100000477; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.43.1",nocase; classtype:trojan-activity; sid:100000478; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.75.8",nocase; classtype:trojan-activity; sid:100000479; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.18.38.144",nocase; classtype:trojan-activity; sid:100000480; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.106.217",nocase; classtype:trojan-activity; sid:100000481; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.108.227",nocase; classtype:trojan-activity; sid:100000482; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.108.79",nocase; classtype:trojan-activity; sid:100000483; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.33.161",nocase; classtype:trojan-activity; sid:100000484; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.119.21",nocase; classtype:trojan-activity; sid:100000485; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.124.203",nocase; classtype:trojan-activity; sid:100000486; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.182.97.232",nocase; classtype:trojan-activity; sid:100000487; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.183.115.103",nocase; classtype:trojan-activity; sid:100000488; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.14.112",nocase; classtype:trojan-activity; sid:100000489; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.172.199",nocase; classtype:trojan-activity; sid:100000490; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.195.161",nocase; classtype:trojan-activity; sid:100000491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.245.61",nocase; classtype:trojan-activity; sid:100000492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.137.195",nocase; classtype:trojan-activity; sid:100000493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.227.244",nocase; classtype:trojan-activity; sid:100000494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.150.85",nocase; classtype:trojan-activity; sid:100000495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.187.206",nocase; classtype:trojan-activity; sid:100000496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.215.221",nocase; classtype:trojan-activity; sid:100000497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.240.20",nocase; classtype:trojan-activity; sid:100000498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.204.30.144",nocase; classtype:trojan-activity; sid:100000499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.250.129.231",nocase; classtype:trojan-activity; sid:100000500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.105.221",nocase; classtype:trojan-activity; sid:100000501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.14.251",nocase; classtype:trojan-activity; sid:100000502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.131.155",nocase; classtype:trojan-activity; sid:100000503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.140.73",nocase; classtype:trojan-activity; sid:100000504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.46",nocase; classtype:trojan-activity; sid:100000505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.71",nocase; classtype:trojan-activity; sid:100000506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.144.75",nocase; classtype:trojan-activity; sid:100000507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.148.115",nocase; classtype:trojan-activity; sid:100000508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.155.57",nocase; classtype:trojan-activity; sid:100000509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.175.41",nocase; classtype:trojan-activity; sid:100000510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.195.90",nocase; classtype:trojan-activity; sid:100000511; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.206.43",nocase; classtype:trojan-activity; sid:100000512; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.232.62",nocase; classtype:trojan-activity; sid:100000513; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.132.113.2",nocase; classtype:trojan-activity; sid:100000514; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.15.69.83",nocase; classtype:trojan-activity; sid:100000515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.6",nocase; classtype:trojan-activity; sid:100000516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.7",nocase; classtype:trojan-activity; sid:100000517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.8",nocase; classtype:trojan-activity; sid:100000518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.9",nocase; classtype:trojan-activity; sid:100000519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.207.39.227",nocase; classtype:trojan-activity; sid:100000520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.25.204.189",nocase; classtype:trojan-activity; sid:100000521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.0.255.173",nocase; classtype:trojan-activity; sid:100000522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.12.153.54",nocase; classtype:trojan-activity; sid:100000523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.142.222.22",nocase; classtype:trojan-activity; sid:100000524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.150.213.110",nocase; classtype:trojan-activity; sid:100000525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.151.248.134",nocase; classtype:trojan-activity; sid:100000526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.180",nocase; classtype:trojan-activity; sid:100000527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.183",nocase; classtype:trojan-activity; sid:100000528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.185",nocase; classtype:trojan-activity; sid:100000529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.186",nocase; classtype:trojan-activity; sid:100000530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.188",nocase; classtype:trojan-activity; sid:100000531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.193",nocase; classtype:trojan-activity; sid:100000532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.201",nocase; classtype:trojan-activity; sid:100000533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.204",nocase; classtype:trojan-activity; sid:100000534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.208",nocase; classtype:trojan-activity; sid:100000535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.209",nocase; classtype:trojan-activity; sid:100000536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.212",nocase; classtype:trojan-activity; sid:100000537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.215",nocase; classtype:trojan-activity; sid:100000538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.233",nocase; classtype:trojan-activity; sid:100000539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.206",nocase; classtype:trojan-activity; sid:100000540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.240",nocase; classtype:trojan-activity; sid:100000541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.127.187",nocase; classtype:trojan-activity; sid:100000542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.99.127",nocase; classtype:trojan-activity; sid:100000543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.210.89.79",nocase; classtype:trojan-activity; sid:100000544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.43.33.202",nocase; classtype:trojan-activity; sid:100000545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.66.60",nocase; classtype:trojan-activity; sid:100000546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.93.115",nocase; classtype:trojan-activity; sid:100000547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.8.11",nocase; classtype:trojan-activity; sid:100000548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.7.75.99",nocase; classtype:trojan-activity; sid:100000549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.173.168",nocase; classtype:trojan-activity; sid:100000550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.114.164",nocase; classtype:trojan-activity; sid:100000551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.96.8",nocase; classtype:trojan-activity; sid:100000552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.121.44.222",nocase; classtype:trojan-activity; sid:100000553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.122.71.122",nocase; classtype:trojan-activity; sid:100000554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.123.53.25",nocase; classtype:trojan-activity; sid:100000555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.127.155.220",nocase; classtype:trojan-activity; sid:100000556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.141.11.56",nocase; classtype:trojan-activity; sid:100000557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.15.142.137",nocase; classtype:trojan-activity; sid:100000558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.159.22.144",nocase; classtype:trojan-activity; sid:100000559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.170.234.142",nocase; classtype:trojan-activity; sid:100000560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.185.31.2",nocase; classtype:trojan-activity; sid:100000561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.190.36.8",nocase; classtype:trojan-activity; sid:100000562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.20.104.26",nocase; classtype:trojan-activity; sid:100000563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.225.11.163",nocase; classtype:trojan-activity; sid:100000564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.23.57.130",nocase; classtype:trojan-activity; sid:100000565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.230.171.198",nocase; classtype:trojan-activity; sid:100000566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.231.103.95",nocase; classtype:trojan-activity; sid:100000567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.237.226.202",nocase; classtype:trojan-activity; sid:100000568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.239.15.74",nocase; classtype:trojan-activity; sid:100000569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.24.116.173",nocase; classtype:trojan-activity; sid:100000570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.254.43.215",nocase; classtype:trojan-activity; sid:100000571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.254.76.17",nocase; classtype:trojan-activity; sid:100000572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.98.151",nocase; classtype:trojan-activity; sid:100000573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.88.99.236",nocase; classtype:trojan-activity; sid:100000574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.100.150.204",nocase; classtype:trojan-activity; sid:100000575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.159.178.39",nocase; classtype:trojan-activity; sid:100000576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.160.147.53",nocase; classtype:trojan-activity; sid:100000577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.176.44.34",nocase; classtype:trojan-activity; sid:100000578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.188.86.225",nocase; classtype:trojan-activity; sid:100000579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.66.28",nocase; classtype:trojan-activity; sid:100000580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.72.23",nocase; classtype:trojan-activity; sid:100000581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.79.27",nocase; classtype:trojan-activity; sid:100000582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.37.85",nocase; classtype:trojan-activity; sid:100000583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.41.23",nocase; classtype:trojan-activity; sid:100000584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.29.37",nocase; classtype:trojan-activity; sid:100000585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.33.214",nocase; classtype:trojan-activity; sid:100000586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.0.240.58",nocase; classtype:trojan-activity; sid:100000587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.54.57",nocase; classtype:trojan-activity; sid:100000588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.238",nocase; classtype:trojan-activity; sid:100000589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.244",nocase; classtype:trojan-activity; sid:100000590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.170.237",nocase; classtype:trojan-activity; sid:100000591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.182.187",nocase; classtype:trojan-activity; sid:100000592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.19.248",nocase; classtype:trojan-activity; sid:100000593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.200.98",nocase; classtype:trojan-activity; sid:100000594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.238.188",nocase; classtype:trojan-activity; sid:100000595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.128.133.91",nocase; classtype:trojan-activity; sid:100000596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.129.84.36",nocase; classtype:trojan-activity; sid:100000597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.208.52",nocase; classtype:trojan-activity; sid:100000598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.27.19",nocase; classtype:trojan-activity; sid:100000599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.37.182",nocase; classtype:trojan-activity; sid:100000600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.131.186.250",nocase; classtype:trojan-activity; sid:100000601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.132.219.147",nocase; classtype:trojan-activity; sid:100000602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.125.77",nocase; classtype:trojan-activity; sid:100000603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.98.135",nocase; classtype:trojan-activity; sid:100000604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.134.14.130",nocase; classtype:trojan-activity; sid:100000605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.134.50.186",nocase; classtype:trojan-activity; sid:100000606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.199.130",nocase; classtype:trojan-activity; sid:100000607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.248.210",nocase; classtype:trojan-activity; sid:100000608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.153.80.178",nocase; classtype:trojan-activity; sid:100000609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.116.116",nocase; classtype:trojan-activity; sid:100000610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.236.114",nocase; classtype:trojan-activity; sid:100000611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.94.1",nocase; classtype:trojan-activity; sid:100000612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.156.136.21",nocase; classtype:trojan-activity; sid:100000613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.68.119",nocase; classtype:trojan-activity; sid:100000614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.8.100",nocase; classtype:trojan-activity; sid:100000615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.183.121.60",nocase; classtype:trojan-activity; sid:100000616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.191.164.92",nocase; classtype:trojan-activity; sid:100000617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.191.62.239",nocase; classtype:trojan-activity; sid:100000618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.101.163",nocase; classtype:trojan-activity; sid:100000619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.194.233",nocase; classtype:trojan-activity; sid:100000620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.149.235",nocase; classtype:trojan-activity; sid:100000621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.53.237",nocase; classtype:trojan-activity; sid:100000622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.235.37",nocase; classtype:trojan-activity; sid:100000623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.35.146",nocase; classtype:trojan-activity; sid:100000624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.52.79",nocase; classtype:trojan-activity; sid:100000625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.60.238",nocase; classtype:trojan-activity; sid:100000626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.112.240",nocase; classtype:trojan-activity; sid:100000627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.184.191",nocase; classtype:trojan-activity; sid:100000628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.98.141",nocase; classtype:trojan-activity; sid:100000629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.212.29.154",nocase; classtype:trojan-activity; sid:100000630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.213.225.130",nocase; classtype:trojan-activity; sid:100000631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.130.162",nocase; classtype:trojan-activity; sid:100000632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.152.249",nocase; classtype:trojan-activity; sid:100000633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.116.110",nocase; classtype:trojan-activity; sid:100000634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.184.57",nocase; classtype:trojan-activity; sid:100000635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.235.226.3",nocase; classtype:trojan-activity; sid:100000636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.103.89",nocase; classtype:trojan-activity; sid:100000637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.181.57",nocase; classtype:trojan-activity; sid:100000638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.79.61",nocase; classtype:trojan-activity; sid:100000639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.148.58",nocase; classtype:trojan-activity; sid:100000640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.184.124",nocase; classtype:trojan-activity; sid:100000641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.28.217.23",nocase; classtype:trojan-activity; sid:100000642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.5.242",nocase; classtype:trojan-activity; sid:100000643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.119.108.87",nocase; classtype:trojan-activity; sid:100000644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.221.150",nocase; classtype:trojan-activity; sid:100000645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.76.230",nocase; classtype:trojan-activity; sid:100000646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.130.40.31",nocase; classtype:trojan-activity; sid:100000647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.104.82",nocase; classtype:trojan-activity; sid:100000648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.151.135",nocase; classtype:trojan-activity; sid:100000649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.203.190",nocase; classtype:trojan-activity; sid:100000650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.24.185",nocase; classtype:trojan-activity; sid:100000651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.26.243",nocase; classtype:trojan-activity; sid:100000652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.54.33",nocase; classtype:trojan-activity; sid:100000653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.132.110.150",nocase; classtype:trojan-activity; sid:100000654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.135.34.49",nocase; classtype:trojan-activity; sid:100000655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.136.175",nocase; classtype:trojan-activity; sid:100000656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.236.6",nocase; classtype:trojan-activity; sid:100000657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.160.126.238",nocase; classtype:trojan-activity; sid:100000658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.65.64",nocase; classtype:trojan-activity; sid:100000659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.72.102",nocase; classtype:trojan-activity; sid:100000660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.165.123.7",nocase; classtype:trojan-activity; sid:100000661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.187.111.160",nocase; classtype:trojan-activity; sid:100000662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.199.56.198",nocase; classtype:trojan-activity; sid:100000663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.230.174.233",nocase; classtype:trojan-activity; sid:100000664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.254.251.54",nocase; classtype:trojan-activity; sid:100000665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.5.92.20",nocase; classtype:trojan-activity; sid:100000666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.6.0.4",nocase; classtype:trojan-activity; sid:100000667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.67.89.28",nocase; classtype:trojan-activity; sid:100000668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.7.254.85",nocase; classtype:trojan-activity; sid:100000669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.80.46.73",nocase; classtype:trojan-activity; sid:100000670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.91.135.234",nocase; classtype:trojan-activity; sid:100000671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.91.237.147",nocase; classtype:trojan-activity; sid:100000672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.93.94.207",nocase; classtype:trojan-activity; sid:100000673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.128.28.161",nocase; classtype:trojan-activity; sid:100000674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.142.93.34",nocase; classtype:trojan-activity; sid:100000675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.191.113.212",nocase; classtype:trojan-activity; sid:100000676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.1.235",nocase; classtype:trojan-activity; sid:100000677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.73.6",nocase; classtype:trojan-activity; sid:100000678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.75.22",nocase; classtype:trojan-activity; sid:100000679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.215.9",nocase; classtype:trojan-activity; sid:100000680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.53.9",nocase; classtype:trojan-activity; sid:100000681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.79.200.104",nocase; classtype:trojan-activity; sid:100000682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"128.116.133.92",nocase; classtype:trojan-activity; sid:100000683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"130.255.159.133",nocase; classtype:trojan-activity; sid:100000684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"134.195.139.4",nocase; classtype:trojan-activity; sid:100000685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"135.148.36.127",nocase; classtype:trojan-activity; sid:100000686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"138.99.204.224",nocase; classtype:trojan-activity; sid:100000687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.159.226.180",nocase; classtype:trojan-activity; sid:100000688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.170.173.198",nocase; classtype:trojan-activity; sid:100000689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.216.102.151",nocase; classtype:trojan-activity; sid:100000690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.227.46.137",nocase; classtype:trojan-activity; sid:100000691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.102.17.222",nocase; classtype:trojan-activity; sid:100000692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.102.97.204",nocase; classtype:trojan-activity; sid:100000693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.136.80.242",nocase; classtype:trojan-activity; sid:100000694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.51",nocase; classtype:trojan-activity; sid:100000695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.160.34.50",nocase; classtype:trojan-activity; sid:100000696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.189.247.118",nocase; classtype:trojan-activity; sid:100000697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.241.227.216",nocase; classtype:trojan-activity; sid:100000698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.37.222.190",nocase; classtype:trojan-activity; sid:100000699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.45.127.110",nocase; classtype:trojan-activity; sid:100000700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.25.17",nocase; classtype:trojan-activity; sid:100000701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.98.241",nocase; classtype:trojan-activity; sid:100000702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.55.29.2",nocase; classtype:trojan-activity; sid:100000703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"141.105.65.94",nocase; classtype:trojan-activity; sid:100000704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.11.216.5",nocase; classtype:trojan-activity; sid:100000705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.177.56.127",nocase; classtype:trojan-activity; sid:100000706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"146.71.79.230",nocase; classtype:trojan-activity; sid:100000707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"148.69.108.177",nocase; classtype:trojan-activity; sid:100000708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.20.176.179",nocase; classtype:trojan-activity; sid:100000709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.134",nocase; classtype:trojan-activity; sid:100000710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.172",nocase; classtype:trojan-activity; sid:100000711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.184",nocase; classtype:trojan-activity; sid:100000712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.38",nocase; classtype:trojan-activity; sid:100000713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.99",nocase; classtype:trojan-activity; sid:100000714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.3.124.223",nocase; classtype:trojan-activity; sid:100000715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.3.85.55",nocase; classtype:trojan-activity; sid:100000716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14karatvisions.com",nocase; classtype:trojan-activity; sid:100000717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"150.116.207.99",nocase; classtype:trojan-activity; sid:100000718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.177.163.87",nocase; classtype:trojan-activity; sid:100000719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.33.230.191",nocase; classtype:trojan-activity; sid:100000720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.234.167",nocase; classtype:trojan-activity; sid:100000721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.47.145",nocase; classtype:trojan-activity; sid:100000722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.152.106",nocase; classtype:trojan-activity; sid:100000723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.135.92",nocase; classtype:trojan-activity; sid:100000724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"155.138.134.44",nocase; classtype:trojan-activity; sid:100000725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.101.165.14",nocase; classtype:trojan-activity; sid:100000726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.174.213.128",nocase; classtype:trojan-activity; sid:100000727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.51.125.115",nocase; classtype:trojan-activity; sid:100000728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"159.224.74.112",nocase; classtype:trojan-activity; sid:100000729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.194.28.60",nocase; classtype:trojan-activity; sid:100000730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.209.98.174",nocase; classtype:trojan-activity; sid:100000731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.53.206.228",nocase; classtype:trojan-activity; sid:100000732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"165.90.16.5",nocase; classtype:trojan-activity; sid:100000733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"170.81.238.178",nocase; classtype:trojan-activity; sid:100000734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.113.36.216",nocase; classtype:trojan-activity; sid:100000735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.113.38.107",nocase; classtype:trojan-activity; sid:100000736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.121.255.10",nocase; classtype:trojan-activity; sid:100000737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.114.181",nocase; classtype:trojan-activity; sid:100000738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.176.217",nocase; classtype:trojan-activity; sid:100000739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.179.178",nocase; classtype:trojan-activity; sid:100000740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.162.156",nocase; classtype:trojan-activity; sid:100000741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.174.198",nocase; classtype:trojan-activity; sid:100000742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.105.36.168",nocase; classtype:trojan-activity; sid:100000743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.114.244.127",nocase; classtype:trojan-activity; sid:100000744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.185",nocase; classtype:trojan-activity; sid:100000745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.190",nocase; classtype:trojan-activity; sid:100000746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.79.106",nocase; classtype:trojan-activity; sid:100000747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.81.19",nocase; classtype:trojan-activity; sid:100000748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.93.194.114",nocase; classtype:trojan-activity; sid:100000749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.167.85.89",nocase; classtype:trojan-activity; sid:100000750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.169.46.85",nocase; classtype:trojan-activity; sid:100000751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.19.58.108",nocase; classtype:trojan-activity; sid:100000752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.233.85.171",nocase; classtype:trojan-activity; sid:100000753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.235.209.70",nocase; classtype:trojan-activity; sid:100000754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.25.113.8",nocase; classtype:trojan-activity; sid:100000755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.95.134",nocase; classtype:trojan-activity; sid:100000756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.97.25",nocase; classtype:trojan-activity; sid:100000757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.119.108",nocase; classtype:trojan-activity; sid:100000758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.92.166",nocase; classtype:trojan-activity; sid:100000759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.106.33.85",nocase; classtype:trojan-activity; sid:100000760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.48.181.23",nocase; classtype:trojan-activity; sid:100000761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.61.3.149",nocase; classtype:trojan-activity; sid:100000762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.73.246.193",nocase; classtype:trojan-activity; sid:100000763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.81.78.7",nocase; classtype:trojan-activity; sid:100000764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.83.73.163",nocase; classtype:trojan-activity; sid:100000765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.10.147.167",nocase; classtype:trojan-activity; sid:100000766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.11.193.66",nocase; classtype:trojan-activity; sid:100000767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.11.65.112",nocase; classtype:trojan-activity; sid:100000768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.117.66.74",nocase; classtype:trojan-activity; sid:100000769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.145.200.216",nocase; classtype:trojan-activity; sid:100000770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.169.13.182",nocase; classtype:trojan-activity; sid:100000771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.201.104.192",nocase; classtype:trojan-activity; sid:100000772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.208.230.8",nocase; classtype:trojan-activity; sid:100000773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.42.46.118",nocase; classtype:trojan-activity; sid:100000774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.9.24.110",nocase; classtype:trojan-activity; sid:100000775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.9.90.89",nocase; classtype:trojan-activity; sid:100000776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.14",nocase; classtype:trojan-activity; sid:100000777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.249",nocase; classtype:trojan-activity; sid:100000778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.35",nocase; classtype:trojan-activity; sid:100000779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.63",nocase; classtype:trojan-activity; sid:100000780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.66",nocase; classtype:trojan-activity; sid:100000781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.67",nocase; classtype:trojan-activity; sid:100000782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.104",nocase; classtype:trojan-activity; sid:100000783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.113",nocase; classtype:trojan-activity; sid:100000784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.60",nocase; classtype:trojan-activity; sid:100000785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.65",nocase; classtype:trojan-activity; sid:100000786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.66",nocase; classtype:trojan-activity; sid:100000787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.68",nocase; classtype:trojan-activity; sid:100000788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.84",nocase; classtype:trojan-activity; sid:100000789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.91",nocase; classtype:trojan-activity; sid:100000790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.93",nocase; classtype:trojan-activity; sid:100000791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.12.117.70",nocase; classtype:trojan-activity; sid:100000792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.4.115",nocase; classtype:trojan-activity; sid:100000793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.115",nocase; classtype:trojan-activity; sid:100000794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.127",nocase; classtype:trojan-activity; sid:100000795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.9.243",nocase; classtype:trojan-activity; sid:100000796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.124.7.225",nocase; classtype:trojan-activity; sid:100000797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.221.188.251",nocase; classtype:trojan-activity; sid:100000798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.240.84.106",nocase; classtype:trojan-activity; sid:100000799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.11.92.78",nocase; classtype:trojan-activity; sid:100000800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.131.226.235",nocase; classtype:trojan-activity; sid:100000801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.229.64.218",nocase; classtype:trojan-activity; sid:100000802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.54.82.154",nocase; classtype:trojan-activity; sid:100000803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.86.99.5",nocase; classtype:trojan-activity; sid:100000804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.124.182.187",nocase; classtype:trojan-activity; sid:100000805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.142.15",nocase; classtype:trojan-activity; sid:100000806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.150.174.65",nocase; classtype:trojan-activity; sid:100000807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.151.143.2",nocase; classtype:trojan-activity; sid:100000808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.165.122.141",nocase; classtype:trojan-activity; sid:100000809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.0.200",nocase; classtype:trojan-activity; sid:100000810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.137",nocase; classtype:trojan-activity; sid:100000811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.179",nocase; classtype:trojan-activity; sid:100000812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.248",nocase; classtype:trojan-activity; sid:100000813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.249",nocase; classtype:trojan-activity; sid:100000814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.250",nocase; classtype:trojan-activity; sid:100000815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.44",nocase; classtype:trojan-activity; sid:100000816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.80",nocase; classtype:trojan-activity; sid:100000817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.151",nocase; classtype:trojan-activity; sid:100000818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.7",nocase; classtype:trojan-activity; sid:100000819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.110",nocase; classtype:trojan-activity; sid:100000820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.232",nocase; classtype:trojan-activity; sid:100000821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.171",nocase; classtype:trojan-activity; sid:100000822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.67",nocase; classtype:trojan-activity; sid:100000823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.98",nocase; classtype:trojan-activity; sid:100000824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.155",nocase; classtype:trojan-activity; sid:100000825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.69",nocase; classtype:trojan-activity; sid:100000826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.95",nocase; classtype:trojan-activity; sid:100000827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.193",nocase; classtype:trojan-activity; sid:100000828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.0",nocase; classtype:trojan-activity; sid:100000829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.245",nocase; classtype:trojan-activity; sid:100000830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.83",nocase; classtype:trojan-activity; sid:100000831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.105",nocase; classtype:trojan-activity; sid:100000832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.87",nocase; classtype:trojan-activity; sid:100000833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.129",nocase; classtype:trojan-activity; sid:100000834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.26",nocase; classtype:trojan-activity; sid:100000835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.126",nocase; classtype:trojan-activity; sid:100000836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.239",nocase; classtype:trojan-activity; sid:100000837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.252",nocase; classtype:trojan-activity; sid:100000838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.190",nocase; classtype:trojan-activity; sid:100000839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.195",nocase; classtype:trojan-activity; sid:100000840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.206",nocase; classtype:trojan-activity; sid:100000841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.135",nocase; classtype:trojan-activity; sid:100000842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.139",nocase; classtype:trojan-activity; sid:100000843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.140",nocase; classtype:trojan-activity; sid:100000844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.147",nocase; classtype:trojan-activity; sid:100000845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.159",nocase; classtype:trojan-activity; sid:100000846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.46",nocase; classtype:trojan-activity; sid:100000847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.58",nocase; classtype:trojan-activity; sid:100000848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.114",nocase; classtype:trojan-activity; sid:100000849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.110",nocase; classtype:trojan-activity; sid:100000850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.209",nocase; classtype:trojan-activity; sid:100000851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.101",nocase; classtype:trojan-activity; sid:100000852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.138",nocase; classtype:trojan-activity; sid:100000853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.30",nocase; classtype:trojan-activity; sid:100000854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.112",nocase; classtype:trojan-activity; sid:100000855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.146",nocase; classtype:trojan-activity; sid:100000856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.102",nocase; classtype:trojan-activity; sid:100000857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.114",nocase; classtype:trojan-activity; sid:100000858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.69",nocase; classtype:trojan-activity; sid:100000859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.70",nocase; classtype:trojan-activity; sid:100000860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.93",nocase; classtype:trojan-activity; sid:100000861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.123",nocase; classtype:trojan-activity; sid:100000862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.151",nocase; classtype:trojan-activity; sid:100000863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.199",nocase; classtype:trojan-activity; sid:100000864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.228",nocase; classtype:trojan-activity; sid:100000865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.28",nocase; classtype:trojan-activity; sid:100000866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.74",nocase; classtype:trojan-activity; sid:100000867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.9",nocase; classtype:trojan-activity; sid:100000868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.1",nocase; classtype:trojan-activity; sid:100000869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.168",nocase; classtype:trojan-activity; sid:100000870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.191",nocase; classtype:trojan-activity; sid:100000871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.2",nocase; classtype:trojan-activity; sid:100000872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.202",nocase; classtype:trojan-activity; sid:100000873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.248",nocase; classtype:trojan-activity; sid:100000874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.26",nocase; classtype:trojan-activity; sid:100000875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.30",nocase; classtype:trojan-activity; sid:100000876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.91",nocase; classtype:trojan-activity; sid:100000877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.131",nocase; classtype:trojan-activity; sid:100000878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.155",nocase; classtype:trojan-activity; sid:100000879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.4",nocase; classtype:trojan-activity; sid:100000880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.14",nocase; classtype:trojan-activity; sid:100000881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.160",nocase; classtype:trojan-activity; sid:100000882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.220",nocase; classtype:trojan-activity; sid:100000883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.88",nocase; classtype:trojan-activity; sid:100000884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.129",nocase; classtype:trojan-activity; sid:100000885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.252",nocase; classtype:trojan-activity; sid:100000886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.46",nocase; classtype:trojan-activity; sid:100000887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.202",nocase; classtype:trojan-activity; sid:100000888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.231",nocase; classtype:trojan-activity; sid:100000889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.43",nocase; classtype:trojan-activity; sid:100000890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.222",nocase; classtype:trojan-activity; sid:100000891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.254",nocase; classtype:trojan-activity; sid:100000892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.199",nocase; classtype:trojan-activity; sid:100000893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.215",nocase; classtype:trojan-activity; sid:100000894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.108",nocase; classtype:trojan-activity; sid:100000895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.116",nocase; classtype:trojan-activity; sid:100000896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.251",nocase; classtype:trojan-activity; sid:100000897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.7",nocase; classtype:trojan-activity; sid:100000898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.73",nocase; classtype:trojan-activity; sid:100000899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.118",nocase; classtype:trojan-activity; sid:100000900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.61",nocase; classtype:trojan-activity; sid:100000901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.23",nocase; classtype:trojan-activity; sid:100000902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.37",nocase; classtype:trojan-activity; sid:100000903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.75",nocase; classtype:trojan-activity; sid:100000904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.163",nocase; classtype:trojan-activity; sid:100000905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.174",nocase; classtype:trojan-activity; sid:100000906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.91",nocase; classtype:trojan-activity; sid:100000907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.209",nocase; classtype:trojan-activity; sid:100000908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.5",nocase; classtype:trojan-activity; sid:100000909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.117",nocase; classtype:trojan-activity; sid:100000910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.70",nocase; classtype:trojan-activity; sid:100000911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.97",nocase; classtype:trojan-activity; sid:100000912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.149",nocase; classtype:trojan-activity; sid:100000913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.237",nocase; classtype:trojan-activity; sid:100000914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.144",nocase; classtype:trojan-activity; sid:100000915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.176",nocase; classtype:trojan-activity; sid:100000916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.146",nocase; classtype:trojan-activity; sid:100000917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.172",nocase; classtype:trojan-activity; sid:100000918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.117",nocase; classtype:trojan-activity; sid:100000919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.152",nocase; classtype:trojan-activity; sid:100000920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.177",nocase; classtype:trojan-activity; sid:100000921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.56",nocase; classtype:trojan-activity; sid:100000922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.215",nocase; classtype:trojan-activity; sid:100000923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.114",nocase; classtype:trojan-activity; sid:100000924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.171",nocase; classtype:trojan-activity; sid:100000925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.213",nocase; classtype:trojan-activity; sid:100000926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.32",nocase; classtype:trojan-activity; sid:100000927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.37",nocase; classtype:trojan-activity; sid:100000928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.46",nocase; classtype:trojan-activity; sid:100000929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.239",nocase; classtype:trojan-activity; sid:100000930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.47",nocase; classtype:trojan-activity; sid:100000931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.21",nocase; classtype:trojan-activity; sid:100000932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.172",nocase; classtype:trojan-activity; sid:100000933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.214",nocase; classtype:trojan-activity; sid:100000934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.133",nocase; classtype:trojan-activity; sid:100000935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.151",nocase; classtype:trojan-activity; sid:100000936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.213",nocase; classtype:trojan-activity; sid:100000937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.73",nocase; classtype:trojan-activity; sid:100000938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.146",nocase; classtype:trojan-activity; sid:100000939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.220",nocase; classtype:trojan-activity; sid:100000940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.89",nocase; classtype:trojan-activity; sid:100000941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.162",nocase; classtype:trojan-activity; sid:100000942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.7",nocase; classtype:trojan-activity; sid:100000943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.217",nocase; classtype:trojan-activity; sid:100000944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.247",nocase; classtype:trojan-activity; sid:100000945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.253",nocase; classtype:trojan-activity; sid:100000946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.36",nocase; classtype:trojan-activity; sid:100000947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.83",nocase; classtype:trojan-activity; sid:100000948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.126",nocase; classtype:trojan-activity; sid:100000949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.218",nocase; classtype:trojan-activity; sid:100000950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.57",nocase; classtype:trojan-activity; sid:100000951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.6",nocase; classtype:trojan-activity; sid:100000952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.103",nocase; classtype:trojan-activity; sid:100000953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.132",nocase; classtype:trojan-activity; sid:100000954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.200",nocase; classtype:trojan-activity; sid:100000955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.144",nocase; classtype:trojan-activity; sid:100000956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.72",nocase; classtype:trojan-activity; sid:100000957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.136",nocase; classtype:trojan-activity; sid:100000958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.228",nocase; classtype:trojan-activity; sid:100000959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.101",nocase; classtype:trojan-activity; sid:100000960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.6",nocase; classtype:trojan-activity; sid:100000961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.121",nocase; classtype:trojan-activity; sid:100000962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.223",nocase; classtype:trojan-activity; sid:100000963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.229",nocase; classtype:trojan-activity; sid:100000964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.238",nocase; classtype:trojan-activity; sid:100000965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.244",nocase; classtype:trojan-activity; sid:100000966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.0",nocase; classtype:trojan-activity; sid:100000967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.217",nocase; classtype:trojan-activity; sid:100000968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.70",nocase; classtype:trojan-activity; sid:100000969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.90",nocase; classtype:trojan-activity; sid:100000970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.201",nocase; classtype:trojan-activity; sid:100000971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.205",nocase; classtype:trojan-activity; sid:100000972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.214",nocase; classtype:trojan-activity; sid:100000973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.26",nocase; classtype:trojan-activity; sid:100000974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.129",nocase; classtype:trojan-activity; sid:100000975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.137",nocase; classtype:trojan-activity; sid:100000976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.41",nocase; classtype:trojan-activity; sid:100000977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.42",nocase; classtype:trojan-activity; sid:100000978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.8",nocase; classtype:trojan-activity; sid:100000979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.143",nocase; classtype:trojan-activity; sid:100000980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.51",nocase; classtype:trojan-activity; sid:100000981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.57",nocase; classtype:trojan-activity; sid:100000982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.10",nocase; classtype:trojan-activity; sid:100000983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.177",nocase; classtype:trojan-activity; sid:100000984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.236",nocase; classtype:trojan-activity; sid:100000985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.56",nocase; classtype:trojan-activity; sid:100000986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.180",nocase; classtype:trojan-activity; sid:100000987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.212",nocase; classtype:trojan-activity; sid:100000988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.216",nocase; classtype:trojan-activity; sid:100000989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.151",nocase; classtype:trojan-activity; sid:100000990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.254",nocase; classtype:trojan-activity; sid:100000991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.5",nocase; classtype:trojan-activity; sid:100000992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.58",nocase; classtype:trojan-activity; sid:100000993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.14",nocase; classtype:trojan-activity; sid:100000994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.211",nocase; classtype:trojan-activity; sid:100000995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.11",nocase; classtype:trojan-activity; sid:100000996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.82",nocase; classtype:trojan-activity; sid:100000997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.87",nocase; classtype:trojan-activity; sid:100000998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.134",nocase; classtype:trojan-activity; sid:100000999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.183",nocase; classtype:trojan-activity; sid:100001000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.79",nocase; classtype:trojan-activity; sid:100001001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.33",nocase; classtype:trojan-activity; sid:100001002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.115",nocase; classtype:trojan-activity; sid:100001003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.140",nocase; classtype:trojan-activity; sid:100001004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.141",nocase; classtype:trojan-activity; sid:100001005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.157",nocase; classtype:trojan-activity; sid:100001006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.182",nocase; classtype:trojan-activity; sid:100001007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.195",nocase; classtype:trojan-activity; sid:100001008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.134",nocase; classtype:trojan-activity; sid:100001009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.209",nocase; classtype:trojan-activity; sid:100001010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.212",nocase; classtype:trojan-activity; sid:100001011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.221",nocase; classtype:trojan-activity; sid:100001012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.70",nocase; classtype:trojan-activity; sid:100001013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.81",nocase; classtype:trojan-activity; sid:100001014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.21",nocase; classtype:trojan-activity; sid:100001015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.156",nocase; classtype:trojan-activity; sid:100001016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.186",nocase; classtype:trojan-activity; sid:100001017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.192",nocase; classtype:trojan-activity; sid:100001018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.116",nocase; classtype:trojan-activity; sid:100001019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.123",nocase; classtype:trojan-activity; sid:100001020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.209",nocase; classtype:trojan-activity; sid:100001021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.44",nocase; classtype:trojan-activity; sid:100001022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.128",nocase; classtype:trojan-activity; sid:100001023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.153",nocase; classtype:trojan-activity; sid:100001024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.67",nocase; classtype:trojan-activity; sid:100001025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.105",nocase; classtype:trojan-activity; sid:100001026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.14",nocase; classtype:trojan-activity; sid:100001027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.35",nocase; classtype:trojan-activity; sid:100001028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.60",nocase; classtype:trojan-activity; sid:100001029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.79",nocase; classtype:trojan-activity; sid:100001030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.218",nocase; classtype:trojan-activity; sid:100001031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.179",nocase; classtype:trojan-activity; sid:100001032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.222",nocase; classtype:trojan-activity; sid:100001033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.65",nocase; classtype:trojan-activity; sid:100001034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.181",nocase; classtype:trojan-activity; sid:100001035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.244",nocase; classtype:trojan-activity; sid:100001036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.47",nocase; classtype:trojan-activity; sid:100001037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.169",nocase; classtype:trojan-activity; sid:100001038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.2",nocase; classtype:trojan-activity; sid:100001039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.242",nocase; classtype:trojan-activity; sid:100001040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.89",nocase; classtype:trojan-activity; sid:100001041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.226",nocase; classtype:trojan-activity; sid:100001042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.31",nocase; classtype:trojan-activity; sid:100001043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.2",nocase; classtype:trojan-activity; sid:100001044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.247",nocase; classtype:trojan-activity; sid:100001045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.215",nocase; classtype:trojan-activity; sid:100001046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.23",nocase; classtype:trojan-activity; sid:100001047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.53",nocase; classtype:trojan-activity; sid:100001048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.59",nocase; classtype:trojan-activity; sid:100001049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.146",nocase; classtype:trojan-activity; sid:100001050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.42",nocase; classtype:trojan-activity; sid:100001051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.91",nocase; classtype:trojan-activity; sid:100001052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.4",nocase; classtype:trojan-activity; sid:100001053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.121",nocase; classtype:trojan-activity; sid:100001054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.217",nocase; classtype:trojan-activity; sid:100001055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.6",nocase; classtype:trojan-activity; sid:100001056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.179",nocase; classtype:trojan-activity; sid:100001057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.198",nocase; classtype:trojan-activity; sid:100001058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.4",nocase; classtype:trojan-activity; sid:100001059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.4",nocase; classtype:trojan-activity; sid:100001060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.1",nocase; classtype:trojan-activity; sid:100001061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.102",nocase; classtype:trojan-activity; sid:100001062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.92",nocase; classtype:trojan-activity; sid:100001063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.143",nocase; classtype:trojan-activity; sid:100001064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.27",nocase; classtype:trojan-activity; sid:100001065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.32",nocase; classtype:trojan-activity; sid:100001066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.40",nocase; classtype:trojan-activity; sid:100001067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.61",nocase; classtype:trojan-activity; sid:100001068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.120",nocase; classtype:trojan-activity; sid:100001069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.251",nocase; classtype:trojan-activity; sid:100001070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.113",nocase; classtype:trojan-activity; sid:100001071; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.83",nocase; classtype:trojan-activity; sid:100001072; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.120",nocase; classtype:trojan-activity; sid:100001073; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.130",nocase; classtype:trojan-activity; sid:100001074; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.77",nocase; classtype:trojan-activity; sid:100001075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.19.183.14",nocase; classtype:trojan-activity; sid:100001076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.205.101.33",nocase; classtype:trojan-activity; sid:100001077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.21.164.68",nocase; classtype:trojan-activity; sid:100001078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.217.8.194",nocase; classtype:trojan-activity; sid:100001079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.22.117.102",nocase; classtype:trojan-activity; sid:100001080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.222.252.130",nocase; classtype:trojan-activity; sid:100001081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.34.183.30",nocase; classtype:trojan-activity; sid:100001082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.48.235.59",nocase; classtype:trojan-activity; sid:100001083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.95.136.35",nocase; classtype:trojan-activity; sid:100001084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.159.58.134",nocase; classtype:trojan-activity; sid:100001085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.60.84.7",nocase; classtype:trojan-activity; sid:100001086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.99.210.161",nocase; classtype:trojan-activity; sid:100001087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.114.60.229",nocase; classtype:trojan-activity; sid:100001088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.116.203.220",nocase; classtype:trojan-activity; sid:100001089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.122.13.227",nocase; classtype:trojan-activity; sid:100001090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.123.208.250",nocase; classtype:trojan-activity; sid:100001091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.157.66.204",nocase; classtype:trojan-activity; sid:100001092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.175.236.209",nocase; classtype:trojan-activity; sid:100001093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.105.41",nocase; classtype:trojan-activity; sid:100001094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.110.243",nocase; classtype:trojan-activity; sid:100001095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.165.230",nocase; classtype:trojan-activity; sid:100001096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.214.171",nocase; classtype:trojan-activity; sid:100001097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.34.51",nocase; classtype:trojan-activity; sid:100001098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.96.248",nocase; classtype:trojan-activity; sid:100001099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.104.65",nocase; classtype:trojan-activity; sid:100001100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.180.6",nocase; classtype:trojan-activity; sid:100001101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.242.73",nocase; classtype:trojan-activity; sid:100001102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.218.5.171",nocase; classtype:trojan-activity; sid:100001103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.248.80.38",nocase; classtype:trojan-activity; sid:100001104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.111.36",nocase; classtype:trojan-activity; sid:100001105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.53.93",nocase; classtype:trojan-activity; sid:100001106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.94.170.166",nocase; classtype:trojan-activity; sid:100001107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.138.154",nocase; classtype:trojan-activity; sid:100001108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.218.238",nocase; classtype:trojan-activity; sid:100001109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.218.6",nocase; classtype:trojan-activity; sid:100001110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.143.60.163",nocase; classtype:trojan-activity; sid:100001111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.193.107.10",nocase; classtype:trojan-activity; sid:100001112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.222",nocase; classtype:trojan-activity; sid:100001113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.230",nocase; classtype:trojan-activity; sid:100001114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.210.45.42",nocase; classtype:trojan-activity; sid:100001115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.215.47.82",nocase; classtype:trojan-activity; sid:100001116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.224.242.131",nocase; classtype:trojan-activity; sid:100001117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.236.4",nocase; classtype:trojan-activity; sid:100001118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.59.162",nocase; classtype:trojan-activity; sid:100001119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.113.209.187",nocase; classtype:trojan-activity; sid:100001120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.108.244",nocase; classtype:trojan-activity; sid:100001121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.43.47",nocase; classtype:trojan-activity; sid:100001122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.60.73",nocase; classtype:trojan-activity; sid:100001123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.61.252",nocase; classtype:trojan-activity; sid:100001124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.99.150",nocase; classtype:trojan-activity; sid:100001125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.43.185",nocase; classtype:trojan-activity; sid:100001126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.120.8",nocase; classtype:trojan-activity; sid:100001127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.164.128",nocase; classtype:trojan-activity; sid:100001128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.202.130",nocase; classtype:trojan-activity; sid:100001129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.22",nocase; classtype:trojan-activity; sid:100001130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.46",nocase; classtype:trojan-activity; sid:100001131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.26.37",nocase; classtype:trojan-activity; sid:100001132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.152.3",nocase; classtype:trojan-activity; sid:100001133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.160.98.250",nocase; classtype:trojan-activity; sid:100001134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.233.0.252",nocase; classtype:trojan-activity; sid:100001135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.235.252.31",nocase; classtype:trojan-activity; sid:100001136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.53.197.62",nocase; classtype:trojan-activity; sid:100001137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.105.225.154",nocase; classtype:trojan-activity; sid:100001138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.109.169.45",nocase; classtype:trojan-activity; sid:100001139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.128.152.115",nocase; classtype:trojan-activity; sid:100001140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.29.191",nocase; classtype:trojan-activity; sid:100001141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.92.207.147",nocase; classtype:trojan-activity; sid:100001142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.164.185.41",nocase; classtype:trojan-activity; sid:100001143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.175.115.10",nocase; classtype:trojan-activity; sid:100001144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.74.149.230",nocase; classtype:trojan-activity; sid:100001145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.106.209.68",nocase; classtype:trojan-activity; sid:100001146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.107.3.8",nocase; classtype:trojan-activity; sid:100001147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.117.2.107",nocase; classtype:trojan-activity; sid:100001148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.172.110.235",nocase; classtype:trojan-activity; sid:100001149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.174.101.41",nocase; classtype:trojan-activity; sid:100001150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.181.10.234",nocase; classtype:trojan-activity; sid:100001151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.112",nocase; classtype:trojan-activity; sid:100001152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.54",nocase; classtype:trojan-activity; sid:100001153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.77",nocase; classtype:trojan-activity; sid:100001154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.93",nocase; classtype:trojan-activity; sid:100001155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.221.3.244",nocase; classtype:trojan-activity; sid:100001156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.222.58.152",nocase; classtype:trojan-activity; sid:100001157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.228.141.74",nocase; classtype:trojan-activity; sid:100001158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.233.186.151",nocase; classtype:trojan-activity; sid:100001159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.26.113.95",nocase; classtype:trojan-activity; sid:100001160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.34.16.231",nocase; classtype:trojan-activity; sid:100001161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.43.19.151",nocase; classtype:trojan-activity; sid:100001162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.55.1.182",nocase; classtype:trojan-activity; sid:100001163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.68.230.207",nocase; classtype:trojan-activity; sid:100001164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.81.157.186",nocase; classtype:trojan-activity; sid:100001165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.185",nocase; classtype:trojan-activity; sid:100001166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.160",nocase; classtype:trojan-activity; sid:100001167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.161",nocase; classtype:trojan-activity; sid:100001168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.219",nocase; classtype:trojan-activity; sid:100001169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.80",nocase; classtype:trojan-activity; sid:100001170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.151.144.85",nocase; classtype:trojan-activity; sid:100001171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.219.164",nocase; classtype:trojan-activity; sid:100001172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.112",nocase; classtype:trojan-activity; sid:100001173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.77",nocase; classtype:trojan-activity; sid:100001174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.91",nocase; classtype:trojan-activity; sid:100001175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.253.150",nocase; classtype:trojan-activity; sid:100001176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.225.120.173",nocase; classtype:trojan-activity; sid:100001177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.232.44.86",nocase; classtype:trojan-activity; sid:100001178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.28.60.184",nocase; classtype:trojan-activity; sid:100001179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.34.4.40",nocase; classtype:trojan-activity; sid:100001180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.73.188.132",nocase; classtype:trojan-activity; sid:100001181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.12.10.98",nocase; classtype:trojan-activity; sid:100001182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.188.124.229",nocase; classtype:trojan-activity; sid:100001183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.212.200.162",nocase; classtype:trojan-activity; sid:100001184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.21.14",nocase; classtype:trojan-activity; sid:100001185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.231.246",nocase; classtype:trojan-activity; sid:100001186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.113.81.17",nocase; classtype:trojan-activity; sid:100001187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.13.179.87",nocase; classtype:trojan-activity; sid:100001188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.138.200.32",nocase; classtype:trojan-activity; sid:100001189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.143.220.152",nocase; classtype:trojan-activity; sid:100001190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.152.41.141",nocase; classtype:trojan-activity; sid:100001191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.178.50",nocase; classtype:trojan-activity; sid:100001192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.179.127",nocase; classtype:trojan-activity; sid:100001193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.199.59",nocase; classtype:trojan-activity; sid:100001194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.242.242.144",nocase; classtype:trojan-activity; sid:100001195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.81.100.83",nocase; classtype:trojan-activity; sid:100001196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.83.202.25",nocase; classtype:trojan-activity; sid:100001197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"189.222.157.241",nocase; classtype:trojan-activity; sid:100001198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.0.42.106",nocase; classtype:trojan-activity; sid:100001199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.109.178.139",nocase; classtype:trojan-activity; sid:100001200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.110.161.252",nocase; classtype:trojan-activity; sid:100001201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.111.151.164",nocase; classtype:trojan-activity; sid:100001202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.119.207.58",nocase; classtype:trojan-activity; sid:100001203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.12.99.194",nocase; classtype:trojan-activity; sid:100001204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.160",nocase; classtype:trojan-activity; sid:100001205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.3",nocase; classtype:trojan-activity; sid:100001206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.37",nocase; classtype:trojan-activity; sid:100001207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.41",nocase; classtype:trojan-activity; sid:100001208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.42",nocase; classtype:trojan-activity; sid:100001209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.15.212",nocase; classtype:trojan-activity; sid:100001210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.20.14",nocase; classtype:trojan-activity; sid:100001211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.147.16.184",nocase; classtype:trojan-activity; sid:100001212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.159.240.9",nocase; classtype:trojan-activity; sid:100001213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.187.55.150",nocase; classtype:trojan-activity; sid:100001214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.210.214.130",nocase; classtype:trojan-activity; sid:100001215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.177.39",nocase; classtype:trojan-activity; sid:100001216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.226.63",nocase; classtype:trojan-activity; sid:100001217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.49.207",nocase; classtype:trojan-activity; sid:100001218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.214.24.194",nocase; classtype:trojan-activity; sid:100001219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.216.140.123",nocase; classtype:trojan-activity; sid:100001220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.65.206.162",nocase; classtype:trojan-activity; sid:100001221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.73.12.149",nocase; classtype:trojan-activity; sid:100001222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.92.4.231",nocase; classtype:trojan-activity; sid:100001223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.135",nocase; classtype:trojan-activity; sid:100001224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.200",nocase; classtype:trojan-activity; sid:100001225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.41.33",nocase; classtype:trojan-activity; sid:100001226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"191.254.225.48",nocase; classtype:trojan-activity; sid:100001227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"191.255.248.220",nocase; classtype:trojan-activity; sid:100001228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.153.57.63",nocase; classtype:trojan-activity; sid:100001229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.210.175.130",nocase; classtype:trojan-activity; sid:100001230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.185.106",nocase; classtype:trojan-activity; sid:100001231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.209.27",nocase; classtype:trojan-activity; sid:100001232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.220.55",nocase; classtype:trojan-activity; sid:100001233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.228.67",nocase; classtype:trojan-activity; sid:100001234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.230.74",nocase; classtype:trojan-activity; sid:100001235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.3.152.166",nocase; classtype:trojan-activity; sid:100001236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.3.73.205",nocase; classtype:trojan-activity; sid:100001237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.99.240.77",nocase; classtype:trojan-activity; sid:100001238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.142.146.25",nocase; classtype:trojan-activity; sid:100001239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.228.135.144",nocase; classtype:trojan-activity; sid:100001240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.113.107.243",nocase; classtype:trojan-activity; sid:100001241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.147.142.230",nocase; classtype:trojan-activity; sid:100001242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.15.36.167",nocase; classtype:trojan-activity; sid:100001243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.15.36.238",nocase; classtype:trojan-activity; sid:100001244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.152.35.139",nocase; classtype:trojan-activity; sid:100001245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.38.20.199",nocase; classtype:trojan-activity; sid:100001246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.139.126.51",nocase; classtype:trojan-activity; sid:100001247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.162.70.104",nocase; classtype:trojan-activity; sid:100001248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.228.231.218",nocase; classtype:trojan-activity; sid:100001249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.24.94.187",nocase; classtype:trojan-activity; sid:100001250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.202.26.182",nocase; classtype:trojan-activity; sid:100001251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.218.48.82",nocase; classtype:trojan-activity; sid:100001252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.166.203",nocase; classtype:trojan-activity; sid:100001253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.50.27.115",nocase; classtype:trojan-activity; sid:100001254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.133.218",nocase; classtype:trojan-activity; sid:100001255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.174.104",nocase; classtype:trojan-activity; sid:100001256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.207.121",nocase; classtype:trojan-activity; sid:100001257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.213.57",nocase; classtype:trojan-activity; sid:100001258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.251.105",nocase; classtype:trojan-activity; sid:100001259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.251.121",nocase; classtype:trojan-activity; sid:100001260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.46.132.132",nocase; classtype:trojan-activity; sid:100001261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.46.201.76",nocase; classtype:trojan-activity; sid:100001262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"199.188.101.109",nocase; classtype:trojan-activity; sid:100001263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1am.co.nz",nocase; classtype:trojan-activity; sid:100001264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.229.89.119",nocase; classtype:trojan-activity; sid:100001265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.239.22.188",nocase; classtype:trojan-activity; sid:100001266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.37.149.230",nocase; classtype:trojan-activity; sid:100001267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.37.203.65",nocase; classtype:trojan-activity; sid:100001268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.4.24",nocase; classtype:trojan-activity; sid:100001269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.125.182",nocase; classtype:trojan-activity; sid:100001270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.92.184",nocase; classtype:trojan-activity; sid:100001271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.57.122.107",nocase; classtype:trojan-activity; sid:100001272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.83.152.16",nocase; classtype:trojan-activity; sid:100001273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"20.185.42.197",nocase; classtype:trojan-activity; sid:100001274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.105.167.98",nocase; classtype:trojan-activity; sid:100001275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.111.189.70",nocase; classtype:trojan-activity; sid:100001276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.194.4.24",nocase; classtype:trojan-activity; sid:100001277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.2.161.171",nocase; classtype:trojan-activity; sid:100001278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.30.132.50",nocase; classtype:trojan-activity; sid:100001279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.142.147.89",nocase; classtype:trojan-activity; sid:100001280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.170.46.2",nocase; classtype:trojan-activity; sid:100001281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.184.163.170",nocase; classtype:trojan-activity; sid:100001282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.187.102.73",nocase; classtype:trojan-activity; sid:100001283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.200.254.86",nocase; classtype:trojan-activity; sid:100001284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.203.221.20",nocase; classtype:trojan-activity; sid:100001285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.203.27.37",nocase; classtype:trojan-activity; sid:100001286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.107.233.41",nocase; classtype:trojan-activity; sid:100001287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.150.176.100",nocase; classtype:trojan-activity; sid:100001288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.175.103.10",nocase; classtype:trojan-activity; sid:100001289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.29.95.12",nocase; classtype:trojan-activity; sid:100001290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.4.124.58",nocase; classtype:trojan-activity; sid:100001291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.176.114",nocase; classtype:trojan-activity; sid:100001292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.191.174",nocase; classtype:trojan-activity; sid:100001293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.74.236.9",nocase; classtype:trojan-activity; sid:100001294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.109.201.243",nocase; classtype:trojan-activity; sid:100001295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.170.123.78",nocase; classtype:trojan-activity; sid:100001296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.204.232.18",nocase; classtype:trojan-activity; sid:100001297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.229.21.56",nocase; classtype:trojan-activity; sid:100001298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.236.190.28",nocase; classtype:trojan-activity; sid:100001299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.238.86.202",nocase; classtype:trojan-activity; sid:100001300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.70.166.107",nocase; classtype:trojan-activity; sid:100001301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.77.80.159",nocase; classtype:trojan-activity; sid:100001302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.119.166",nocase; classtype:trojan-activity; sid:100001303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.171.138",nocase; classtype:trojan-activity; sid:100001304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.82.36.34",nocase; classtype:trojan-activity; sid:100001305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.93.6.28",nocase; classtype:trojan-activity; sid:100001306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"204.195.116.171",nocase; classtype:trojan-activity; sid:100001307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"205.185.115.74",nocase; classtype:trojan-activity; sid:100001308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"205.185.116.94",nocase; classtype:trojan-activity; sid:100001309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"206.248.137.132",nocase; classtype:trojan-activity; sid:100001310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"206.47.41.166",nocase; classtype:trojan-activity; sid:100001311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.180.228.101",nocase; classtype:trojan-activity; sid:100001312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.5.32.6",nocase; classtype:trojan-activity; sid:100001313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"208.163.58.18",nocase; classtype:trojan-activity; sid:100001314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"208.75.27.157",nocase; classtype:trojan-activity; sid:100001315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.39.50",nocase; classtype:trojan-activity; sid:100001316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.190",nocase; classtype:trojan-activity; sid:100001317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.31",nocase; classtype:trojan-activity; sid:100001318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.124.149.19",nocase; classtype:trojan-activity; sid:100001319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.180.17.140",nocase; classtype:trojan-activity; sid:100001320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.152.122",nocase; classtype:trojan-activity; sid:100001321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.153.142",nocase; classtype:trojan-activity; sid:100001322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.234.93",nocase; classtype:trojan-activity; sid:100001323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.237.70",nocase; classtype:trojan-activity; sid:100001324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.245.109",nocase; classtype:trojan-activity; sid:100001325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.68.242.114",nocase; classtype:trojan-activity; sid:100001326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.96.116.236",nocase; classtype:trojan-activity; sid:100001327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.116.220.37",nocase; classtype:trojan-activity; sid:100001328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.132.204",nocase; classtype:trojan-activity; sid:100001329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.75.220",nocase; classtype:trojan-activity; sid:100001330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.204.215.157",nocase; classtype:trojan-activity; sid:100001331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.66.179",nocase; classtype:trojan-activity; sid:100001332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.93.93",nocase; classtype:trojan-activity; sid:100001333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.216.66.105",nocase; classtype:trojan-activity; sid:100001334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.114.96",nocase; classtype:trojan-activity; sid:100001335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.120.13",nocase; classtype:trojan-activity; sid:100001336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.246.137",nocase; classtype:trojan-activity; sid:100001337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.238.83.238",nocase; classtype:trojan-activity; sid:100001338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.247.113.49",nocase; classtype:trojan-activity; sid:100001339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.247.5.96",nocase; classtype:trojan-activity; sid:100001340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.32.122.110",nocase; classtype:trojan-activity; sid:100001341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.122.86.105",nocase; classtype:trojan-activity; sid:100001342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.143.227.22",nocase; classtype:trojan-activity; sid:100001343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.156.215.178",nocase; classtype:trojan-activity; sid:100001344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.46.197.114",nocase; classtype:trojan-activity; sid:100001345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.56.197.230",nocase; classtype:trojan-activity; sid:100001346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.8.251.211",nocase; classtype:trojan-activity; sid:100001347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.8.251.227",nocase; classtype:trojan-activity; sid:100001348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.123.206.197",nocase; classtype:trojan-activity; sid:100001349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.135.178.253",nocase; classtype:trojan-activity; sid:100001350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.14.173.117",nocase; classtype:trojan-activity; sid:100001351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.149.182.113",nocase; classtype:trojan-activity; sid:100001352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.149.190.193",nocase; classtype:trojan-activity; sid:100001353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.99",nocase; classtype:trojan-activity; sid:100001354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.135",nocase; classtype:trojan-activity; sid:100001355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.20",nocase; classtype:trojan-activity; sid:100001356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.237",nocase; classtype:trojan-activity; sid:100001357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.6",nocase; classtype:trojan-activity; sid:100001358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.114.165",nocase; classtype:trojan-activity; sid:100001359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.114.191",nocase; classtype:trojan-activity; sid:100001360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.105",nocase; classtype:trojan-activity; sid:100001361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.11",nocase; classtype:trojan-activity; sid:100001362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.15",nocase; classtype:trojan-activity; sid:100001363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.30",nocase; classtype:trojan-activity; sid:100001364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.71",nocase; classtype:trojan-activity; sid:100001365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.117.151",nocase; classtype:trojan-activity; sid:100001366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.10",nocase; classtype:trojan-activity; sid:100001367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.238",nocase; classtype:trojan-activity; sid:100001368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.65",nocase; classtype:trojan-activity; sid:100001369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.119.236",nocase; classtype:trojan-activity; sid:100001370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.145",nocase; classtype:trojan-activity; sid:100001371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.7",nocase; classtype:trojan-activity; sid:100001372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.46",nocase; classtype:trojan-activity; sid:100001373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.189.178.163",nocase; classtype:trojan-activity; sid:100001374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.240.218.15",nocase; classtype:trojan-activity; sid:100001375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.249.156.189",nocase; classtype:trojan-activity; sid:100001376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.27.8.6",nocase; classtype:trojan-activity; sid:100001377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.254.52",nocase; classtype:trojan-activity; sid:100001378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.255.36",nocase; classtype:trojan-activity; sid:100001379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.255.84",nocase; classtype:trojan-activity; sid:100001380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.127.185.150",nocase; classtype:trojan-activity; sid:100001381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.158.238.236",nocase; classtype:trojan-activity; sid:100001382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.170.240.98",nocase; classtype:trojan-activity; sid:100001383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.183.54.169",nocase; classtype:trojan-activity; sid:100001384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.36.12.98",nocase; classtype:trojan-activity; sid:100001385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"217.11.75.162",nocase; classtype:trojan-activity; sid:100001386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"217.127.133.214",nocase; classtype:trojan-activity; sid:100001387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.12.181.110",nocase; classtype:trojan-activity; sid:100001388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.2.40.34",nocase; classtype:trojan-activity; sid:100001389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.234.165.18",nocase; classtype:trojan-activity; sid:100001390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.238.246.3",nocase; classtype:trojan-activity; sid:100001391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.207.119",nocase; classtype:trojan-activity; sid:100001392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.227.133",nocase; classtype:trojan-activity; sid:100001393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.68.35",nocase; classtype:trojan-activity; sid:100001394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.81.81",nocase; classtype:trojan-activity; sid:100001395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.56.93.129",nocase; classtype:trojan-activity; sid:100001396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.59.116.203",nocase; classtype:trojan-activity; sid:100001397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.79.103.159",nocase; classtype:trojan-activity; sid:100001398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.93.102.63",nocase; classtype:trojan-activity; sid:100001399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.93.102.75",nocase; classtype:trojan-activity; sid:100001400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.102.14",nocase; classtype:trojan-activity; sid:100001401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.29.165",nocase; classtype:trojan-activity; sid:100001402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.186.18",nocase; classtype:trojan-activity; sid:100001403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.139.165",nocase; classtype:trojan-activity; sid:100001404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.150.91",nocase; classtype:trojan-activity; sid:100001405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.214.235",nocase; classtype:trojan-activity; sid:100001406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.241.6.180",nocase; classtype:trojan-activity; sid:100001407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.1.148",nocase; classtype:trojan-activity; sid:100001408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.1.84",nocase; classtype:trojan-activity; sid:100001409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.163.7",nocase; classtype:trojan-activity; sid:100001410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.171.144",nocase; classtype:trojan-activity; sid:100001411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.245.63",nocase; classtype:trojan-activity; sid:100001412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.5.140",nocase; classtype:trojan-activity; sid:100001413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.69.71.186",nocase; classtype:trojan-activity; sid:100001414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.70.238.66",nocase; classtype:trojan-activity; sid:100001415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.80.217.209",nocase; classtype:trojan-activity; sid:100001416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.85.145.194",nocase; classtype:trojan-activity; sid:100001417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"21robo.com",nocase; classtype:trojan-activity; sid:100001418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.118.168.155",nocase; classtype:trojan-activity; sid:100001419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.126.237.74",nocase; classtype:trojan-activity; sid:100001420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.200.22.163",nocase; classtype:trojan-activity; sid:100001421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.71.239.115",nocase; classtype:trojan-activity; sid:100001422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.1.144.183",nocase; classtype:trojan-activity; sid:100001423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.124.78.15",nocase; classtype:trojan-activity; sid:100001424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.125.69",nocase; classtype:trojan-activity; sid:100001425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.136.213",nocase; classtype:trojan-activity; sid:100001426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.202.232.230",nocase; classtype:trojan-activity; sid:100001427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.130.147",nocase; classtype:trojan-activity; sid:100001428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.251.109",nocase; classtype:trojan-activity; sid:100001429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.116.167",nocase; classtype:trojan-activity; sid:100001430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.172.207",nocase; classtype:trojan-activity; sid:100001431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.184.31",nocase; classtype:trojan-activity; sid:100001432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.252.64",nocase; classtype:trojan-activity; sid:100001433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.8.64",nocase; classtype:trojan-activity; sid:100001434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.232.1.82",nocase; classtype:trojan-activity; sid:100001435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.235.137.36",nocase; classtype:trojan-activity; sid:100001436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.112.125",nocase; classtype:trojan-activity; sid:100001437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.32.88",nocase; classtype:trojan-activity; sid:100001438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.34.43",nocase; classtype:trojan-activity; sid:100001439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.43.223",nocase; classtype:trojan-activity; sid:100001440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.68.16",nocase; classtype:trojan-activity; sid:100001441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.108.17.64",nocase; classtype:trojan-activity; sid:100001442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.118.248.149",nocase; classtype:trojan-activity; sid:100001443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.119.65.145",nocase; classtype:trojan-activity; sid:100001444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.132.125.138",nocase; classtype:trojan-activity; sid:100001445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.103.120",nocase; classtype:trojan-activity; sid:100001446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.9.5",nocase; classtype:trojan-activity; sid:100001447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.148.192",nocase; classtype:trojan-activity; sid:100001448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.211.78",nocase; classtype:trojan-activity; sid:100001449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.17.132",nocase; classtype:trojan-activity; sid:100001450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.237.155",nocase; classtype:trojan-activity; sid:100001451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.17.245",nocase; classtype:trojan-activity; sid:100001452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.179.215.189",nocase; classtype:trojan-activity; sid:100001453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.185.116.233",nocase; classtype:trojan-activity; sid:100001454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.186.20.19",nocase; classtype:trojan-activity; sid:100001455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.187.9.178",nocase; classtype:trojan-activity; sid:100001456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.211.72.66",nocase; classtype:trojan-activity; sid:100001457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.236.85.220",nocase; classtype:trojan-activity; sid:100001458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.238.230.7",nocase; classtype:trojan-activity; sid:100001459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.239.83.232",nocase; classtype:trojan-activity; sid:100001460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.248.64.253",nocase; classtype:trojan-activity; sid:100001461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.92.9.126",nocase; classtype:trojan-activity; sid:100001462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.95.190.20",nocase; classtype:trojan-activity; sid:100001463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.99.171.192",nocase; classtype:trojan-activity; sid:100001464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.131.201.82",nocase; classtype:trojan-activity; sid:100001465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.166.117.210",nocase; classtype:trojan-activity; sid:100001466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.167.118.17",nocase; classtype:trojan-activity; sid:100001467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.225.68",nocase; classtype:trojan-activity; sid:100001468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.234.84",nocase; classtype:trojan-activity; sid:100001469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.5.29",nocase; classtype:trojan-activity; sid:100001470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.73.175",nocase; classtype:trojan-activity; sid:100001471; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.115.118.232",nocase; classtype:trojan-activity; sid:100001472; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.125.186.135",nocase; classtype:trojan-activity; sid:100001473; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.126.120.25",nocase; classtype:trojan-activity; sid:100001474; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.228.143.58",nocase; classtype:trojan-activity; sid:100001475; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.24.213.121",nocase; classtype:trojan-activity; sid:100001476; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.149.13",nocase; classtype:trojan-activity; sid:100001477; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.21.167",nocase; classtype:trojan-activity; sid:100001478; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.95.89.21",nocase; classtype:trojan-activity; sid:100001479; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.103.74.180",nocase; classtype:trojan-activity; sid:100001480; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.11.141.134",nocase; classtype:trojan-activity; sid:100001481; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.119.158.74",nocase; classtype:trojan-activity; sid:100001482; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.137.147.95",nocase; classtype:trojan-activity; sid:100001483; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.137.233.132",nocase; classtype:trojan-activity; sid:100001484; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.152.235.88",nocase; classtype:trojan-activity; sid:100001485; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.158.25.98",nocase; classtype:trojan-activity; sid:100001486; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.176.206.12",nocase; classtype:trojan-activity; sid:100001487; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.184.1.41",nocase; classtype:trojan-activity; sid:100001488; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.192.191.109",nocase; classtype:trojan-activity; sid:100001489; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.225.114.161",nocase; classtype:trojan-activity; sid:100001490; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.227.190.78",nocase; classtype:trojan-activity; sid:100001491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.35.245.52",nocase; classtype:trojan-activity; sid:100001492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.39.181.18",nocase; classtype:trojan-activity; sid:100001493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.39.34.242",nocase; classtype:trojan-activity; sid:100001494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.42.229.143",nocase; classtype:trojan-activity; sid:100001495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.45.4.1",nocase; classtype:trojan-activity; sid:100001496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.51.91.113",nocase; classtype:trojan-activity; sid:100001497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.53.163.10",nocase; classtype:trojan-activity; sid:100001498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.53.163.9",nocase; classtype:trojan-activity; sid:100001499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.89.140.190",nocase; classtype:trojan-activity; sid:100001500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.1.245.16",nocase; classtype:trojan-activity; sid:100001501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.1.245.7",nocase; classtype:trojan-activity; sid:100001502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.105.106.201",nocase; classtype:trojan-activity; sid:100001503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.105.152.107",nocase; classtype:trojan-activity; sid:100001504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.116.84.57",nocase; classtype:trojan-activity; sid:100001505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.14.211.219",nocase; classtype:trojan-activity; sid:100001506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.14.81.201",nocase; classtype:trojan-activity; sid:100001507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.141.218.17",nocase; classtype:trojan-activity; sid:100001508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.147.29.52",nocase; classtype:trojan-activity; sid:100001509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.147.40.128",nocase; classtype:trojan-activity; sid:100001510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.184.251.135",nocase; classtype:trojan-activity; sid:100001511; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.193.196.190",nocase; classtype:trojan-activity; sid:100001512; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.193.217.210",nocase; classtype:trojan-activity; sid:100001513; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.149.142",nocase; classtype:trojan-activity; sid:100001514; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.159.98",nocase; classtype:trojan-activity; sid:100001515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.192.66",nocase; classtype:trojan-activity; sid:100001516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.210.20",nocase; classtype:trojan-activity; sid:100001517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.22.217",nocase; classtype:trojan-activity; sid:100001518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.23.215",nocase; classtype:trojan-activity; sid:100001519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.232.65",nocase; classtype:trojan-activity; sid:100001520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.3.194",nocase; classtype:trojan-activity; sid:100001521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.34.48",nocase; classtype:trojan-activity; sid:100001522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.110.211",nocase; classtype:trojan-activity; sid:100001523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.140.229",nocase; classtype:trojan-activity; sid:100001524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.32.146",nocase; classtype:trojan-activity; sid:100001525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.201.183.149",nocase; classtype:trojan-activity; sid:100001526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.202.182.201",nocase; classtype:trojan-activity; sid:100001527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.102.12",nocase; classtype:trojan-activity; sid:100001528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.116.86",nocase; classtype:trojan-activity; sid:100001529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.154.105",nocase; classtype:trojan-activity; sid:100001530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.165.138",nocase; classtype:trojan-activity; sid:100001531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.185.42",nocase; classtype:trojan-activity; sid:100001532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.213.79",nocase; classtype:trojan-activity; sid:100001533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.255.42",nocase; classtype:trojan-activity; sid:100001534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.28.115",nocase; classtype:trojan-activity; sid:100001535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.4.188",nocase; classtype:trojan-activity; sid:100001536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.68.144",nocase; classtype:trojan-activity; sid:100001537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.7.141",nocase; classtype:trojan-activity; sid:100001538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.87.75",nocase; classtype:trojan-activity; sid:100001539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.94.134",nocase; classtype:trojan-activity; sid:100001540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.204.253.74",nocase; classtype:trojan-activity; sid:100001541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.205.178.110",nocase; classtype:trojan-activity; sid:100001542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.136.101",nocase; classtype:trojan-activity; sid:100001543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.154.122",nocase; classtype:trojan-activity; sid:100001544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.80.209",nocase; classtype:trojan-activity; sid:100001545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.151.126",nocase; classtype:trojan-activity; sid:100001546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.155.31",nocase; classtype:trojan-activity; sid:100001547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.170.203",nocase; classtype:trojan-activity; sid:100001548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.119.27",nocase; classtype:trojan-activity; sid:100001549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.164.18",nocase; classtype:trojan-activity; sid:100001550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.237.105",nocase; classtype:trojan-activity; sid:100001551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.247.130",nocase; classtype:trojan-activity; sid:100001552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.25.59",nocase; classtype:trojan-activity; sid:100001553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.34.2",nocase; classtype:trojan-activity; sid:100001554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.92.64",nocase; classtype:trojan-activity; sid:100001555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.208.122",nocase; classtype:trojan-activity; sid:100001556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.231.15",nocase; classtype:trojan-activity; sid:100001557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.107.125",nocase; classtype:trojan-activity; sid:100001558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.234.28",nocase; classtype:trojan-activity; sid:100001559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.236.134",nocase; classtype:trojan-activity; sid:100001560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.32.122",nocase; classtype:trojan-activity; sid:100001561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.44.19",nocase; classtype:trojan-activity; sid:100001562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.63.243",nocase; classtype:trojan-activity; sid:100001563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.104.201",nocase; classtype:trojan-activity; sid:100001564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.109.105",nocase; classtype:trojan-activity; sid:100001565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.175.208",nocase; classtype:trojan-activity; sid:100001566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.255.202",nocase; classtype:trojan-activity; sid:100001567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.66.112",nocase; classtype:trojan-activity; sid:100001568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.84.74",nocase; classtype:trojan-activity; sid:100001569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.214.37.129",nocase; classtype:trojan-activity; sid:100001570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.139.242",nocase; classtype:trojan-activity; sid:100001571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.190.172",nocase; classtype:trojan-activity; sid:100001572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.212.209",nocase; classtype:trojan-activity; sid:100001573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.253.149",nocase; classtype:trojan-activity; sid:100001574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.71.243",nocase; classtype:trojan-activity; sid:100001575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.98.242",nocase; classtype:trojan-activity; sid:100001576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.117.54",nocase; classtype:trojan-activity; sid:100001577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.128.156",nocase; classtype:trojan-activity; sid:100001578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.131.66",nocase; classtype:trojan-activity; sid:100001579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.144.66",nocase; classtype:trojan-activity; sid:100001580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.197.193",nocase; classtype:trojan-activity; sid:100001581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.225.28",nocase; classtype:trojan-activity; sid:100001582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.227.95",nocase; classtype:trojan-activity; sid:100001583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.234.98",nocase; classtype:trojan-activity; sid:100001584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.133.53",nocase; classtype:trojan-activity; sid:100001585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.191.58",nocase; classtype:trojan-activity; sid:100001586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.248.121",nocase; classtype:trojan-activity; sid:100001587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.132.71",nocase; classtype:trojan-activity; sid:100001588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.151.83",nocase; classtype:trojan-activity; sid:100001589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.160.112",nocase; classtype:trojan-activity; sid:100001590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.176.72",nocase; classtype:trojan-activity; sid:100001591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.192.223",nocase; classtype:trojan-activity; sid:100001592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.83.244",nocase; classtype:trojan-activity; sid:100001593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.20.66",nocase; classtype:trojan-activity; sid:100001594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.249.0",nocase; classtype:trojan-activity; sid:100001595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.85.168",nocase; classtype:trojan-activity; sid:100001596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.221.239.223",nocase; classtype:trojan-activity; sid:100001597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.241.223",nocase; classtype:trojan-activity; sid:100001598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.76.80",nocase; classtype:trojan-activity; sid:100001599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.223.242.164",nocase; classtype:trojan-activity; sid:100001600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.24.28.134",nocase; classtype:trojan-activity; sid:100001601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.129.198",nocase; classtype:trojan-activity; sid:100001602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.154.13",nocase; classtype:trojan-activity; sid:100001603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.212.124",nocase; classtype:trojan-activity; sid:100001604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.58.5",nocase; classtype:trojan-activity; sid:100001605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.43.117.98",nocase; classtype:trojan-activity; sid:100001606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.0.98.131",nocase; classtype:trojan-activity; sid:100001607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.11.51.57",nocase; classtype:trojan-activity; sid:100001608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.13.23.180",nocase; classtype:trojan-activity; sid:100001609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.124.130",nocase; classtype:trojan-activity; sid:100001610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.179.83",nocase; classtype:trojan-activity; sid:100001611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.184.59",nocase; classtype:trojan-activity; sid:100001612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.191.243",nocase; classtype:trojan-activity; sid:100001613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.194.67",nocase; classtype:trojan-activity; sid:100001614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.216.132",nocase; classtype:trojan-activity; sid:100001615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.219.28",nocase; classtype:trojan-activity; sid:100001616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.24.115",nocase; classtype:trojan-activity; sid:100001617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.30.65",nocase; classtype:trojan-activity; sid:100001618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.63.203",nocase; classtype:trojan-activity; sid:100001619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.65.233",nocase; classtype:trojan-activity; sid:100001620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.79.66",nocase; classtype:trojan-activity; sid:100001621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.94.16",nocase; classtype:trojan-activity; sid:100001622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.179.201.26",nocase; classtype:trojan-activity; sid:100001623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.195.84.250",nocase; classtype:trojan-activity; sid:100001624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.177",nocase; classtype:trojan-activity; sid:100001625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.69",nocase; classtype:trojan-activity; sid:100001626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.28.7.159",nocase; classtype:trojan-activity; sid:100001627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.30.119.23",nocase; classtype:trojan-activity; sid:100001628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32.208.157.193",nocase; classtype:trojan-activity; sid:100001629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32792.prolocksmithwinterpark.com",nocase; classtype:trojan-activity; sid:100001630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"35.184.169.169",nocase; classtype:trojan-activity; sid:100001631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.108.231.218",nocase; classtype:trojan-activity; sid:100001632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.248.228.64",nocase; classtype:trojan-activity; sid:100001633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.248.83.98",nocase; classtype:trojan-activity; sid:100001634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.250.203.246",nocase; classtype:trojan-activity; sid:100001635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.157.225",nocase; classtype:trojan-activity; sid:100001636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.18.18",nocase; classtype:trojan-activity; sid:100001637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.51.244",nocase; classtype:trojan-activity; sid:100001638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.255.90.219",nocase; classtype:trojan-activity; sid:100001639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.33.128.58",nocase; classtype:trojan-activity; sid:100001640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.33.160.167",nocase; classtype:trojan-activity; sid:100001641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.34.150.236",nocase; classtype:trojan-activity; sid:100001642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.105.159",nocase; classtype:trojan-activity; sid:100001643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.133.125",nocase; classtype:trojan-activity; sid:100001644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.139.36",nocase; classtype:trojan-activity; sid:100001645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.89.18.133",nocase; classtype:trojan-activity; sid:100001646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360.lcy2zzx.pw",nocase; classtype:trojan-activity; sid:100001647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360down7.miiyun.cn",nocase; classtype:trojan-activity; sid:100001648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.222.98.51",nocase; classtype:trojan-activity; sid:100001649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.233.60.68",nocase; classtype:trojan-activity; sid:100001650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.179.221",nocase; classtype:trojan-activity; sid:100001651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.180.172",nocase; classtype:trojan-activity; sid:100001652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.44.238.35",nocase; classtype:trojan-activity; sid:100001653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.49.230.177",nocase; classtype:trojan-activity; sid:100001654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.14.36",nocase; classtype:trojan-activity; sid:100001655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.14.52",nocase; classtype:trojan-activity; sid:100001656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.230.61",nocase; classtype:trojan-activity; sid:100001657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"38.77.14.237",nocase; classtype:trojan-activity; sid:100001658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.245.254",nocase; classtype:trojan-activity; sid:100001659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.98.136",nocase; classtype:trojan-activity; sid:100001660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.117.31.162",nocase; classtype:trojan-activity; sid:100001661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.162.104.119",nocase; classtype:trojan-activity; sid:100001662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.196.34",nocase; classtype:trojan-activity; sid:100001663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.59.160",nocase; classtype:trojan-activity; sid:100001664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.66.44.109",nocase; classtype:trojan-activity; sid:100001665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.104.83",nocase; classtype:trojan-activity; sid:100001666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.125.186",nocase; classtype:trojan-activity; sid:100001667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.146.60",nocase; classtype:trojan-activity; sid:100001668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.148.163",nocase; classtype:trojan-activity; sid:100001669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.206.228",nocase; classtype:trojan-activity; sid:100001670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.124.76",nocase; classtype:trojan-activity; sid:100001671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.171.125",nocase; classtype:trojan-activity; sid:100001672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.249.255",nocase; classtype:trojan-activity; sid:100001673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.60.61",nocase; classtype:trojan-activity; sid:100001674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.167.202",nocase; classtype:trojan-activity; sid:100001675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.67.64",nocase; classtype:trojan-activity; sid:100001676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.10.198",nocase; classtype:trojan-activity; sid:100001677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.163.231",nocase; classtype:trojan-activity; sid:100001678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.168.234",nocase; classtype:trojan-activity; sid:100001679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.203.225",nocase; classtype:trojan-activity; sid:100001680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.237.84",nocase; classtype:trojan-activity; sid:100001681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.132.170",nocase; classtype:trojan-activity; sid:100001682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.194.65",nocase; classtype:trojan-activity; sid:100001683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.235.122",nocase; classtype:trojan-activity; sid:100001684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.33.191",nocase; classtype:trojan-activity; sid:100001685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.78.251",nocase; classtype:trojan-activity; sid:100001686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.113.201",nocase; classtype:trojan-activity; sid:100001687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.114.45",nocase; classtype:trojan-activity; sid:100001688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.14.27",nocase; classtype:trojan-activity; sid:100001689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.150.203",nocase; classtype:trojan-activity; sid:100001690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.197.81",nocase; classtype:trojan-activity; sid:100001691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.209.209",nocase; classtype:trojan-activity; sid:100001692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.48.213",nocase; classtype:trojan-activity; sid:100001693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.63.152",nocase; classtype:trojan-activity; sid:100001694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.94.189",nocase; classtype:trojan-activity; sid:100001695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.163.188",nocase; classtype:trojan-activity; sid:100001696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.166.31",nocase; classtype:trojan-activity; sid:100001697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.218.46",nocase; classtype:trojan-activity; sid:100001698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.91.244",nocase; classtype:trojan-activity; sid:100001699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.93.171",nocase; classtype:trojan-activity; sid:100001700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.127.214",nocase; classtype:trojan-activity; sid:100001701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.18.140",nocase; classtype:trojan-activity; sid:100001702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.191.137",nocase; classtype:trojan-activity; sid:100001703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.205.255",nocase; classtype:trojan-activity; sid:100001704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.24.54",nocase; classtype:trojan-activity; sid:100001705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.36.151",nocase; classtype:trojan-activity; sid:100001706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.37.182",nocase; classtype:trojan-activity; sid:100001707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.251.0",nocase; classtype:trojan-activity; sid:100001708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.27.15",nocase; classtype:trojan-activity; sid:100001709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.29.231",nocase; classtype:trojan-activity; sid:100001710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.70.88",nocase; classtype:trojan-activity; sid:100001711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.83.94.11",nocase; classtype:trojan-activity; sid:100001712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.115.152",nocase; classtype:trojan-activity; sid:100001713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.85.54.4",nocase; classtype:trojan-activity; sid:100001714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.129.233",nocase; classtype:trojan-activity; sid:100001715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.170.209",nocase; classtype:trojan-activity; sid:100001716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.211.20",nocase; classtype:trojan-activity; sid:100001717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.234.187",nocase; classtype:trojan-activity; sid:100001718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.63.58",nocase; classtype:trojan-activity; sid:100001719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.93.109",nocase; classtype:trojan-activity; sid:100001720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.155.96",nocase; classtype:trojan-activity; sid:100001721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.233.131",nocase; classtype:trojan-activity; sid:100001722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.67.238",nocase; classtype:trojan-activity; sid:100001723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.72.9",nocase; classtype:trojan-activity; sid:100001724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.108.109",nocase; classtype:trojan-activity; sid:100001725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.145.11",nocase; classtype:trojan-activity; sid:100001726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.146.198",nocase; classtype:trojan-activity; sid:100001727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.63.23",nocase; classtype:trojan-activity; sid:100001728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.90.86.212",nocase; classtype:trojan-activity; sid:100001729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"40.88.2.151",nocase; classtype:trojan-activity; sid:100001730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.139.209.46",nocase; classtype:trojan-activity; sid:100001731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.165.130.43",nocase; classtype:trojan-activity; sid:100001732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.190.63.174",nocase; classtype:trojan-activity; sid:100001733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.193.192.100",nocase; classtype:trojan-activity; sid:100001734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.219.185.171",nocase; classtype:trojan-activity; sid:100001735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.226.60.115",nocase; classtype:trojan-activity; sid:100001736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.72.203.82",nocase; classtype:trojan-activity; sid:100001737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.133",nocase; classtype:trojan-activity; sid:100001738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.27",nocase; classtype:trojan-activity; sid:100001739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.197",nocase; classtype:trojan-activity; sid:100001740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.202.101.199",nocase; classtype:trojan-activity; sid:100001741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.39.211",nocase; classtype:trojan-activity; sid:100001742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.43.161",nocase; classtype:trojan-activity; sid:100001743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.65.104",nocase; classtype:trojan-activity; sid:100001744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.82.176",nocase; classtype:trojan-activity; sid:100001745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.232.81.179",nocase; classtype:trojan-activity; sid:100001746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.180.147",nocase; classtype:trojan-activity; sid:100001747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.239.26.122",nocase; classtype:trojan-activity; sid:100001748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.56.15.227",nocase; classtype:trojan-activity; sid:100001749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.61.99.155",nocase; classtype:trojan-activity; sid:100001750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.82.217.241",nocase; classtype:trojan-activity; sid:100001751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.84.37.198",nocase; classtype:trojan-activity; sid:100001752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.241.106.183",nocase; classtype:trojan-activity; sid:100001753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.241.108.134",nocase; classtype:trojan-activity; sid:100001754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.252.8.94",nocase; classtype:trojan-activity; sid:100001755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.115.172.148",nocase; classtype:trojan-activity; sid:100001756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.1.242",nocase; classtype:trojan-activity; sid:100001757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.203.192",nocase; classtype:trojan-activity; sid:100001758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.135.134.228",nocase; classtype:trojan-activity; sid:100001759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.182",nocase; classtype:trojan-activity; sid:100001760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.204",nocase; classtype:trojan-activity; sid:100001761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.141.84.182",nocase; classtype:trojan-activity; sid:100001762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.141.84.184",nocase; classtype:trojan-activity; sid:100001763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.118",nocase; classtype:trojan-activity; sid:100001764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.135",nocase; classtype:trojan-activity; sid:100001765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.139",nocase; classtype:trojan-activity; sid:100001766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.196",nocase; classtype:trojan-activity; sid:100001767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.213",nocase; classtype:trojan-activity; sid:100001768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.242",nocase; classtype:trojan-activity; sid:100001769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.27",nocase; classtype:trojan-activity; sid:100001770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.65",nocase; classtype:trojan-activity; sid:100001771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.47",nocase; classtype:trojan-activity; sid:100001772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.94",nocase; classtype:trojan-activity; sid:100001773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.164.140.130",nocase; classtype:trojan-activity; sid:100001774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.165.215.19",nocase; classtype:trojan-activity; sid:100001775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.151",nocase; classtype:trojan-activity; sid:100001776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.22",nocase; classtype:trojan-activity; sid:100001777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.248",nocase; classtype:trojan-activity; sid:100001778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.110.99",nocase; classtype:trojan-activity; sid:100001779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.22.209.58",nocase; classtype:trojan-activity; sid:100001780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.229.53.115",nocase; classtype:trojan-activity; sid:100001781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.23.22.186",nocase; classtype:trojan-activity; sid:100001782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.248.194.48",nocase; classtype:trojan-activity; sid:100001783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.27.253.137",nocase; classtype:trojan-activity; sid:100001784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.51.104.59",nocase; classtype:trojan-activity; sid:100001785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.6.24.251",nocase; classtype:trojan-activity; sid:100001786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.81.235.31",nocase; classtype:trojan-activity; sid:100001787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.85.90.203",nocase; classtype:trojan-activity; sid:100001788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.9.148.37",nocase; classtype:trojan-activity; sid:100001789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.92.108.125",nocase; classtype:trojan-activity; sid:100001790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.117.42.29",nocase; classtype:trojan-activity; sid:100001791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.172.75.231",nocase; classtype:trojan-activity; sid:100001792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.182.173.246",nocase; classtype:trojan-activity; sid:100001793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.20.63.218",nocase; classtype:trojan-activity; sid:100001794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.214.27.4",nocase; classtype:trojan-activity; sid:100001795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.24.130.254",nocase; classtype:trojan-activity; sid:100001796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.241.120.165",nocase; classtype:trojan-activity; sid:100001797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.243.179.115",nocase; classtype:trojan-activity; sid:100001798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.249.33.79",nocase; classtype:trojan-activity; sid:100001799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.25.242.211",nocase; classtype:trojan-activity; sid:100001800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.118.86",nocase; classtype:trojan-activity; sid:100001801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.86.128",nocase; classtype:trojan-activity; sid:100001802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.97.76.242",nocase; classtype:trojan-activity; sid:100001803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.103.219.77",nocase; classtype:trojan-activity; sid:100001804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.145.152.26",nocase; classtype:trojan-activity; sid:100001805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.151.23.172",nocase; classtype:trojan-activity; sid:100001806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.157.97.71",nocase; classtype:trojan-activity; sid:100001807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.16.131.51",nocase; classtype:trojan-activity; sid:100001808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.21.202.98",nocase; classtype:trojan-activity; sid:100001809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.46.231.38",nocase; classtype:trojan-activity; sid:100001810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.119.187.230",nocase; classtype:trojan-activity; sid:100001811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.162.113",nocase; classtype:trojan-activity; sid:100001812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.87.36",nocase; classtype:trojan-activity; sid:100001813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.143.43.93",nocase; classtype:trojan-activity; sid:100001814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.156.35.166",nocase; classtype:trojan-activity; sid:100001815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.158.201.200",nocase; classtype:trojan-activity; sid:100001816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.20.121",nocase; classtype:trojan-activity; sid:100001817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.21.3",nocase; classtype:trojan-activity; sid:100001818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.174.182.99",nocase; classtype:trojan-activity; sid:100001819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.170.49",nocase; classtype:trojan-activity; sid:100001820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.178.183",nocase; classtype:trojan-activity; sid:100001821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.179.129",nocase; classtype:trojan-activity; sid:100001822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.68.221.252",nocase; classtype:trojan-activity; sid:100001823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.188.62.111",nocase; classtype:trojan-activity; sid:100001824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.2.70.50",nocase; classtype:trojan-activity; sid:100001825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.53.146.179",nocase; classtype:trojan-activity; sid:100001826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.79.75.210",nocase; classtype:trojan-activity; sid:100001827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.95.226.154",nocase; classtype:trojan-activity; sid:100001828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.115.174.102",nocase; classtype:trojan-activity; sid:100001829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.115.174.106",nocase; classtype:trojan-activity; sid:100001830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.121.91.255",nocase; classtype:trojan-activity; sid:100001831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.252.47.29",nocase; classtype:trojan-activity; sid:100001832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.114.136",nocase; classtype:trojan-activity; sid:100001833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.180.122",nocase; classtype:trojan-activity; sid:100001834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.114.246.26",nocase; classtype:trojan-activity; sid:100001835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.162.92",nocase; classtype:trojan-activity; sid:100001836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.174.4",nocase; classtype:trojan-activity; sid:100001837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.125.191.4",nocase; classtype:trojan-activity; sid:100001838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.126.247.118",nocase; classtype:trojan-activity; sid:100001839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.141.122.109",nocase; classtype:trojan-activity; sid:100001840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.166.120",nocase; classtype:trojan-activity; sid:100001841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.200.124",nocase; classtype:trojan-activity; sid:100001842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.143.189.75",nocase; classtype:trojan-activity; sid:100001843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.218.67.253",nocase; classtype:trojan-activity; sid:100001844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.22.212.107",nocase; classtype:trojan-activity; sid:100001845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.226.129.29",nocase; classtype:trojan-activity; sid:100001846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.230.89.42",nocase; classtype:trojan-activity; sid:100001847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.238.42.192",nocase; classtype:trojan-activity; sid:100001848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.240.147.97",nocase; classtype:trojan-activity; sid:100001849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.241.78.55",nocase; classtype:trojan-activity; sid:100001850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.243.126.133",nocase; classtype:trojan-activity; sid:100001851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.243.208.225",nocase; classtype:trojan-activity; sid:100001852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.142.227",nocase; classtype:trojan-activity; sid:100001853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.79.174",nocase; classtype:trojan-activity; sid:100001854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.84.131",nocase; classtype:trojan-activity; sid:100001855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.48.154.143",nocase; classtype:trojan-activity; sid:100001856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.153",nocase; classtype:trojan-activity; sid:100001857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.39",nocase; classtype:trojan-activity; sid:100001858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.76.151.51",nocase; classtype:trojan-activity; sid:100001859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.97.206.33",nocase; classtype:trojan-activity; sid:100001860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.0.211.161",nocase; classtype:trojan-activity; sid:100001861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.102.168.189",nocase; classtype:trojan-activity; sid:100001862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.202.3",nocase; classtype:trojan-activity; sid:100001863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.214.4",nocase; classtype:trojan-activity; sid:100001864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.237.51",nocase; classtype:trojan-activity; sid:100001865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.246.125",nocase; classtype:trojan-activity; sid:100001866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.23.114.97",nocase; classtype:trojan-activity; sid:100001867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.58.117.226",nocase; classtype:trojan-activity; sid:100001868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.18.144",nocase; classtype:trojan-activity; sid:100001869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.96.37.124",nocase; classtype:trojan-activity; sid:100001870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.169.237",nocase; classtype:trojan-activity; sid:100001871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.10.91.242",nocase; classtype:trojan-activity; sid:100001872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.13.61.12",nocase; classtype:trojan-activity; sid:100001873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.164.130.220",nocase; classtype:trojan-activity; sid:100001874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.175.124.27",nocase; classtype:trojan-activity; sid:100001875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.20.217.142",nocase; classtype:trojan-activity; sid:100001876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.208.135.42",nocase; classtype:trojan-activity; sid:100001877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.122.57",nocase; classtype:trojan-activity; sid:100001878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.186.185",nocase; classtype:trojan-activity; sid:100001879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.216.23",nocase; classtype:trojan-activity; sid:100001880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.233.94",nocase; classtype:trojan-activity; sid:100001881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.6.112",nocase; classtype:trojan-activity; sid:100001882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.100.83",nocase; classtype:trojan-activity; sid:100001883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.111.39",nocase; classtype:trojan-activity; sid:100001884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.202.218",nocase; classtype:trojan-activity; sid:100001885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.206.246",nocase; classtype:trojan-activity; sid:100001886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.218.31",nocase; classtype:trojan-activity; sid:100001887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.220.167",nocase; classtype:trojan-activity; sid:100001888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.254.178",nocase; classtype:trojan-activity; sid:100001889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.162.59",nocase; classtype:trojan-activity; sid:100001890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.83.55",nocase; classtype:trojan-activity; sid:100001891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.195.111",nocase; classtype:trojan-activity; sid:100001892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.177.196",nocase; classtype:trojan-activity; sid:100001893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.86.208",nocase; classtype:trojan-activity; sid:100001894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.223.84.102",nocase; classtype:trojan-activity; sid:100001895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.15.104",nocase; classtype:trojan-activity; sid:100001896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.4.72",nocase; classtype:trojan-activity; sid:100001897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.51.127",nocase; classtype:trojan-activity; sid:100001898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.60.174",nocase; classtype:trojan-activity; sid:100001899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.8.81",nocase; classtype:trojan-activity; sid:100001900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.26.104.150",nocase; classtype:trojan-activity; sid:100001901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.10.121",nocase; classtype:trojan-activity; sid:100001902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.8.43",nocase; classtype:trojan-activity; sid:100001903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.99.254",nocase; classtype:trojan-activity; sid:100001904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.164.96.98",nocase; classtype:trojan-activity; sid:100001905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.91.194",nocase; classtype:trojan-activity; sid:100001906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.247.224.66",nocase; classtype:trojan-activity; sid:100001907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.253.94.230",nocase; classtype:trojan-activity; sid:100001908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.41.230.161",nocase; classtype:trojan-activity; sid:100001909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.47.220.169",nocase; classtype:trojan-activity; sid:100001910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.103.217",nocase; classtype:trojan-activity; sid:100001911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.199.47",nocase; classtype:trojan-activity; sid:100001912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.30.172",nocase; classtype:trojan-activity; sid:100001913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.9.166",nocase; classtype:trojan-activity; sid:100001914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.99.161",nocase; classtype:trojan-activity; sid:100001915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.117.237",nocase; classtype:trojan-activity; sid:100001916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.89.220",nocase; classtype:trojan-activity; sid:100001917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.103.56",nocase; classtype:trojan-activity; sid:100001918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.64.63",nocase; classtype:trojan-activity; sid:100001919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.69.77",nocase; classtype:trojan-activity; sid:100001920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.180.67",nocase; classtype:trojan-activity; sid:100001921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.181.7",nocase; classtype:trojan-activity; sid:100001922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.57.96.116",nocase; classtype:trojan-activity; sid:100001923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.170.60",nocase; classtype:trojan-activity; sid:100001924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.73.220",nocase; classtype:trojan-activity; sid:100001925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.61.218.23",nocase; classtype:trojan-activity; sid:100001926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.65.172.121",nocase; classtype:trojan-activity; sid:100001927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.0.22",nocase; classtype:trojan-activity; sid:100001928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.104.46",nocase; classtype:trojan-activity; sid:100001929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.110.59",nocase; classtype:trojan-activity; sid:100001930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.195",nocase; classtype:trojan-activity; sid:100001931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.86",nocase; classtype:trojan-activity; sid:100001932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.255.60",nocase; classtype:trojan-activity; sid:100001933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.45.130",nocase; classtype:trojan-activity; sid:100001934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.98.144.75",nocase; classtype:trojan-activity; sid:100001935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.1.98.131",nocase; classtype:trojan-activity; sid:100001936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.141.73.58",nocase; classtype:trojan-activity; sid:100001937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.131.205",nocase; classtype:trojan-activity; sid:100001938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.143.46",nocase; classtype:trojan-activity; sid:100001939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.155.61",nocase; classtype:trojan-activity; sid:100001940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.227.31",nocase; classtype:trojan-activity; sid:100001941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.31.126.33",nocase; classtype:trojan-activity; sid:100001942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.149.66",nocase; classtype:trojan-activity; sid:100001943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.222.98",nocase; classtype:trojan-activity; sid:100001944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.43.207.148",nocase; classtype:trojan-activity; sid:100001945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.90.165.236",nocase; classtype:trojan-activity; sid:100001946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"63.245.122.93",nocase; classtype:trojan-activity; sid:100001947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"64.233.154.99",nocase; classtype:trojan-activity; sid:100001948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.125.128.196",nocase; classtype:trojan-activity; sid:100001949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.21.58.252",nocase; classtype:trojan-activity; sid:100001950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.26.155.131",nocase; classtype:trojan-activity; sid:100001951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.35.61.255",nocase; classtype:trojan-activity; sid:100001952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.229.214.115",nocase; classtype:trojan-activity; sid:100001953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.57.55.210",nocase; classtype:trojan-activity; sid:100001954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.74.7.197",nocase; classtype:trojan-activity; sid:100001955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.97.181.196",nocase; classtype:trojan-activity; sid:100001956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.245.151.203",nocase; classtype:trojan-activity; sid:100001957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.3.169.223",nocase; classtype:trojan-activity; sid:100001958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.8.138.101",nocase; classtype:trojan-activity; sid:100001959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.83.49.234",nocase; classtype:trojan-activity; sid:100001960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.84.138.165",nocase; classtype:trojan-activity; sid:100001961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.148.103.248",nocase; classtype:trojan-activity; sid:100001962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.151.244.128",nocase; classtype:trojan-activity; sid:100001963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.174.182.226",nocase; classtype:trojan-activity; sid:100001964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.175.107.153",nocase; classtype:trojan-activity; sid:100001965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.188.144.143",nocase; classtype:trojan-activity; sid:100001966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.204.88.29",nocase; classtype:trojan-activity; sid:100001967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.106.84",nocase; classtype:trojan-activity; sid:100001968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.119.241",nocase; classtype:trojan-activity; sid:100001969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.78.33.33",nocase; classtype:trojan-activity; sid:100001970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.115.37.205",nocase; classtype:trojan-activity; sid:100001971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.120.237.255",nocase; classtype:trojan-activity; sid:100001972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.123.245.151",nocase; classtype:trojan-activity; sid:100001973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.124.231.110",nocase; classtype:trojan-activity; sid:100001974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.127.214.47",nocase; classtype:trojan-activity; sid:100001975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.146.232.34",nocase; classtype:trojan-activity; sid:100001976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.165.173.49",nocase; classtype:trojan-activity; sid:100001977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.196.158.227",nocase; classtype:trojan-activity; sid:100001978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.222.157.166",nocase; classtype:trojan-activity; sid:100001979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.229.0.133",nocase; classtype:trojan-activity; sid:100001980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.63.73.234",nocase; classtype:trojan-activity; sid:100001981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.115.194",nocase; classtype:trojan-activity; sid:100001982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.227.186",nocase; classtype:trojan-activity; sid:100001983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.76.240.206",nocase; classtype:trojan-activity; sid:100001984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.115.31.30",nocase; classtype:trojan-activity; sid:100001985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.118.240.88",nocase; classtype:trojan-activity; sid:100001986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.167.10.180",nocase; classtype:trojan-activity; sid:100001987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.236.190.250",nocase; classtype:trojan-activity; sid:100001988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.25.5.105",nocase; classtype:trojan-activity; sid:100001989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.93.129.118",nocase; classtype:trojan-activity; sid:100001990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.127.148.69",nocase; classtype:trojan-activity; sid:100001991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.146.190.91",nocase; classtype:trojan-activity; sid:100001992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.204.63.239",nocase; classtype:trojan-activity; sid:100001993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.29.48.164",nocase; classtype:trojan-activity; sid:100001994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.34.191.213",nocase; classtype:trojan-activity; sid:100001995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.40.234.166",nocase; classtype:trojan-activity; sid:100001996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.106.142",nocase; classtype:trojan-activity; sid:100001997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.2.122",nocase; classtype:trojan-activity; sid:100001998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.235.106",nocase; classtype:trojan-activity; sid:100001999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.47.133.58",nocase; classtype:trojan-activity; sid:100002000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.71.60.69",nocase; classtype:trojan-activity; sid:100002001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.85.106.211",nocase; classtype:trojan-activity; sid:100002002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.17.22.30",nocase; classtype:trojan-activity; sid:100002003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.186.139.38",nocase; classtype:trojan-activity; sid:100002004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.180.98",nocase; classtype:trojan-activity; sid:100002005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.200.62",nocase; classtype:trojan-activity; sid:100002006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.202.249.109",nocase; classtype:trojan-activity; sid:100002007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.214.69.226",nocase; classtype:trojan-activity; sid:100002008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.229.230.118",nocase; classtype:trojan-activity; sid:100002009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.31.40.122",nocase; classtype:trojan-activity; sid:100002010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.204.216.103",nocase; classtype:trojan-activity; sid:100002011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.70.164.42",nocase; classtype:trojan-activity; sid:100002012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.101.1.159",nocase; classtype:trojan-activity; sid:100002013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.108.224.112",nocase; classtype:trojan-activity; sid:100002014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.194.117.165",nocase; classtype:trojan-activity; sid:100002015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.195.115.176",nocase; classtype:trojan-activity; sid:100002016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.199.84.77",nocase; classtype:trojan-activity; sid:100002017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.64.139.223",nocase; classtype:trojan-activity; sid:100002018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.75.165.81",nocase; classtype:trojan-activity; sid:100002019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.127.141.52",nocase; classtype:trojan-activity; sid:100002020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.83.102.27",nocase; classtype:trojan-activity; sid:100002021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.99.213.61",nocase; classtype:trojan-activity; sid:100002022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.170.11.82",nocase; classtype:trojan-activity; sid:100002023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.178.22.145",nocase; classtype:trojan-activity; sid:100002024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.217.92.231",nocase; classtype:trojan-activity; sid:100002025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.250.199.133",nocase; classtype:trojan-activity; sid:100002026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.254.129.227",nocase; classtype:trojan-activity; sid:100002027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.84.134.33",nocase; classtype:trojan-activity; sid:100002028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.95.12.137",nocase; classtype:trojan-activity; sid:100002029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.111.182.31",nocase; classtype:trojan-activity; sid:100002030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.237.25.210",nocase; classtype:trojan-activity; sid:100002031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.50.153",nocase; classtype:trojan-activity; sid:100002032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.52.220",nocase; classtype:trojan-activity; sid:100002033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.89.203.238",nocase; classtype:trojan-activity; sid:100002034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77st.net",nocase; classtype:trojan-activity; sid:100002035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.145.224.45",nocase; classtype:trojan-activity; sid:100002036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.186.155.18",nocase; classtype:trojan-activity; sid:100002037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.141.144",nocase; classtype:trojan-activity; sid:100002038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.240.125",nocase; classtype:trojan-activity; sid:100002039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.41.200",nocase; classtype:trojan-activity; sid:100002040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.168.64",nocase; classtype:trojan-activity; sid:100002041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.188.141",nocase; classtype:trojan-activity; sid:100002042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.104.157",nocase; classtype:trojan-activity; sid:100002043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.176.163",nocase; classtype:trojan-activity; sid:100002044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.27.157",nocase; classtype:trojan-activity; sid:100002045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.23.172.81",nocase; classtype:trojan-activity; sid:100002046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.8.225.77",nocase; classtype:trojan-activity; sid:100002047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.11.195.121",nocase; classtype:trojan-activity; sid:100002048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.13.49.221",nocase; classtype:trojan-activity; sid:100002049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.130.253.13",nocase; classtype:trojan-activity; sid:100002050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.147.123.48",nocase; classtype:trojan-activity; sid:100002051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.175.42.244",nocase; classtype:trojan-activity; sid:100002052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.21.84.63",nocase; classtype:trojan-activity; sid:100002053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.7.170.58",nocase; classtype:trojan-activity; sid:100002054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.79.58.94",nocase; classtype:trojan-activity; sid:100002055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.8.70.162",nocase; classtype:trojan-activity; sid:100002056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.9.88.185",nocase; classtype:trojan-activity; sid:100002057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.107.89.207",nocase; classtype:trojan-activity; sid:100002058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.19.101.218",nocase; classtype:trojan-activity; sid:100002059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.211.181.77",nocase; classtype:trojan-activity; sid:100002060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.217.12.7",nocase; classtype:trojan-activity; sid:100002061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.99.128.61",nocase; classtype:trojan-activity; sid:100002062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.136.146.213",nocase; classtype:trojan-activity; sid:100002063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.165.44.109",nocase; classtype:trojan-activity; sid:100002064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.191.40.58",nocase; classtype:trojan-activity; sid:100002065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.213.141.184",nocase; classtype:trojan-activity; sid:100002066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.215.199.29",nocase; classtype:trojan-activity; sid:100002067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.187.113",nocase; classtype:trojan-activity; sid:100002068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.195.216",nocase; classtype:trojan-activity; sid:100002069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.237.128.200",nocase; classtype:trojan-activity; sid:100002070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.244.219.41",nocase; classtype:trojan-activity; sid:100002071; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.246.225.203",nocase; classtype:trojan-activity; sid:100002072; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.92.36.96",nocase; classtype:trojan-activity; sid:100002073; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.103.108.72",nocase; classtype:trojan-activity; sid:100002074; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.135.196.130",nocase; classtype:trojan-activity; sid:100002075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.212.178",nocase; classtype:trojan-activity; sid:100002076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.85.112",nocase; classtype:trojan-activity; sid:100002077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.207.61.194",nocase; classtype:trojan-activity; sid:100002078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.209.250.155",nocase; classtype:trojan-activity; sid:100002079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.211.156.38",nocase; classtype:trojan-activity; sid:100002080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.59.31.181",nocase; classtype:trojan-activity; sid:100002081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.110.252",nocase; classtype:trojan-activity; sid:100002082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.53.77",nocase; classtype:trojan-activity; sid:100002083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.138.72",nocase; classtype:trojan-activity; sid:100002084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.139.92",nocase; classtype:trojan-activity; sid:100002085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.154.214",nocase; classtype:trojan-activity; sid:100002086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.187.109",nocase; classtype:trojan-activity; sid:100002087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.100.54",nocase; classtype:trojan-activity; sid:100002088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.106.65",nocase; classtype:trojan-activity; sid:100002089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.108.172",nocase; classtype:trojan-activity; sid:100002090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.131.158",nocase; classtype:trojan-activity; sid:100002091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.19.42",nocase; classtype:trojan-activity; sid:100002092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.197.254",nocase; classtype:trojan-activity; sid:100002093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.215.149",nocase; classtype:trojan-activity; sid:100002094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.232.68",nocase; classtype:trojan-activity; sid:100002095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.234.195",nocase; classtype:trojan-activity; sid:100002096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.246.96",nocase; classtype:trojan-activity; sid:100002097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.28.57",nocase; classtype:trojan-activity; sid:100002098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.4.57",nocase; classtype:trojan-activity; sid:100002099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.55.84",nocase; classtype:trojan-activity; sid:100002100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.73.245",nocase; classtype:trojan-activity; sid:100002101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.98.51",nocase; classtype:trojan-activity; sid:100002102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.165.237.163",nocase; classtype:trojan-activity; sid:100002103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.147.99",nocase; classtype:trojan-activity; sid:100002104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.218.42",nocase; classtype:trojan-activity; sid:100002105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.242.253.154",nocase; classtype:trojan-activity; sid:100002106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.252.9.37",nocase; classtype:trojan-activity; sid:100002107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.210.219.213",nocase; classtype:trojan-activity; sid:100002108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.212.219.127",nocase; classtype:trojan-activity; sid:100002109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.50.118",nocase; classtype:trojan-activity; sid:100002110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.95.204",nocase; classtype:trojan-activity; sid:100002111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.238.24.35",nocase; classtype:trojan-activity; sid:100002112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.247.83.74",nocase; classtype:trojan-activity; sid:100002113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.254.39.129",nocase; classtype:trojan-activity; sid:100002114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.33.111.227",nocase; classtype:trojan-activity; sid:100002115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.39.248.2",nocase; classtype:trojan-activity; sid:100002116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.40.127.242",nocase; classtype:trojan-activity; sid:100002117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.42.20.217",nocase; classtype:trojan-activity; sid:100002118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com",nocase; classtype:trojan-activity; sid:100002119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.11.216",nocase; classtype:trojan-activity; sid:100002120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.123.251",nocase; classtype:trojan-activity; sid:100002121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.135.187",nocase; classtype:trojan-activity; sid:100002122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.180.33",nocase; classtype:trojan-activity; sid:100002123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.224.141",nocase; classtype:trojan-activity; sid:100002124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.241.2",nocase; classtype:trojan-activity; sid:100002125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.214.149.236",nocase; classtype:trojan-activity; sid:100002126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.64.181.50",nocase; classtype:trojan-activity; sid:100002127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.64.203.204",nocase; classtype:trojan-activity; sid:100002128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.74.215.180",nocase; classtype:trojan-activity; sid:100002129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.130.227",nocase; classtype:trojan-activity; sid:100002130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.195.129",nocase; classtype:trojan-activity; sid:100002131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"86.35.43.220",nocase; classtype:trojan-activity; sid:100002132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.172.19.130",nocase; classtype:trojan-activity; sid:100002133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.61.89.40",nocase; classtype:trojan-activity; sid:100002134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.119.171.253",nocase; classtype:trojan-activity; sid:100002135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.208.71",nocase; classtype:trojan-activity; sid:100002136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.219.179",nocase; classtype:trojan-activity; sid:100002137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.225.222.128",nocase; classtype:trojan-activity; sid:100002138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.247.96.19",nocase; classtype:trojan-activity; sid:100002139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.136.231",nocase; classtype:trojan-activity; sid:100002140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.51.139",nocase; classtype:trojan-activity; sid:100002141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.249.244.180",nocase; classtype:trojan-activity; sid:100002142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.204.12",nocase; classtype:trojan-activity; sid:100002143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.226.26",nocase; classtype:trojan-activity; sid:100002144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.240.245",nocase; classtype:trojan-activity; sid:100002145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.254.90",nocase; classtype:trojan-activity; sid:100002146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.122.183.130",nocase; classtype:trojan-activity; sid:100002147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.136.197.170",nocase; classtype:trojan-activity; sid:100002148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.22.152.244",nocase; classtype:trojan-activity; sid:100002149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.29.213.33",nocase; classtype:trojan-activity; sid:100002150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.85.166",nocase; classtype:trojan-activity; sid:100002151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8poieq.bn.files.1drv.com",nocase; classtype:trojan-activity; sid:100002152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"90.152.144.139",nocase; classtype:trojan-activity; sid:100002153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.132.197.39",nocase; classtype:trojan-activity; sid:100002154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.138.215.5",nocase; classtype:trojan-activity; sid:100002155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.177.139.132",nocase; classtype:trojan-activity; sid:100002156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.187.103.32",nocase; classtype:trojan-activity; sid:100002157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.205.173.252",nocase; classtype:trojan-activity; sid:100002158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.212.150.241",nocase; classtype:trojan-activity; sid:100002159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.214.124.141",nocase; classtype:trojan-activity; sid:100002160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.217.104.185",nocase; classtype:trojan-activity; sid:100002161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.233.112.188",nocase; classtype:trojan-activity; sid:100002162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.239.168.83",nocase; classtype:trojan-activity; sid:100002163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.92.16.244",nocase; classtype:trojan-activity; sid:100002164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.98.4.181",nocase; classtype:trojan-activity; sid:100002165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.114.191.82",nocase; classtype:trojan-activity; sid:100002166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.241.78.114",nocase; classtype:trojan-activity; sid:100002167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.27.246.202",nocase; classtype:trojan-activity; sid:100002168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.54.237.237",nocase; classtype:trojan-activity; sid:100002169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.83.62.139",nocase; classtype:trojan-activity; sid:100002170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.85.18.138",nocase; classtype:trojan-activity; sid:100002171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.159.169.190",nocase; classtype:trojan-activity; sid:100002172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.21.224.154",nocase; classtype:trojan-activity; sid:100002173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.39.115.176",nocase; classtype:trojan-activity; sid:100002174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.39.79.41",nocase; classtype:trojan-activity; sid:100002175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.137.16",nocase; classtype:trojan-activity; sid:100002176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.182.249",nocase; classtype:trojan-activity; sid:100002177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.206.56",nocase; classtype:trojan-activity; sid:100002178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.57.43.233",nocase; classtype:trojan-activity; sid:100002179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.73.99.102",nocase; classtype:trojan-activity; sid:100002180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.136.69.199",nocase; classtype:trojan-activity; sid:100002181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.143.53.34",nocase; classtype:trojan-activity; sid:100002182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.154.17.170",nocase; classtype:trojan-activity; sid:100002183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.200.16.22",nocase; classtype:trojan-activity; sid:100002184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.224.83.208",nocase; classtype:trojan-activity; sid:100002185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.53.120.109",nocase; classtype:trojan-activity; sid:100002186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.85.0.3",nocase; classtype:trojan-activity; sid:100002187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.132.129.250",nocase; classtype:trojan-activity; sid:100002188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.154.20.231",nocase; classtype:trojan-activity; sid:100002189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.158.19.130",nocase; classtype:trojan-activity; sid:100002190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.113.227",nocase; classtype:trojan-activity; sid:100002191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.113.52",nocase; classtype:trojan-activity; sid:100002192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.201.34",nocase; classtype:trojan-activity; sid:100002193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.60.146.134",nocase; classtype:trojan-activity; sid:100002194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.66.196.63",nocase; classtype:trojan-activity; sid:100002195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.9.120.40",nocase; classtype:trojan-activity; sid:100002196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.239.73.246",nocase; classtype:trojan-activity; sid:100002197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.47.147.169",nocase; classtype:trojan-activity; sid:100002198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.68.140.254",nocase; classtype:trojan-activity; sid:100002199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.96.199.75",nocase; classtype:trojan-activity; sid:100002200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.0.210.218",nocase; classtype:trojan-activity; sid:100002201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.113.239.207",nocase; classtype:trojan-activity; sid:100002202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.116.72.119",nocase; classtype:trojan-activity; sid:100002203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.128.147.115",nocase; classtype:trojan-activity; sid:100002204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.178.242.44",nocase; classtype:trojan-activity; sid:100002205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.30.24.54",nocase; classtype:trojan-activity; sid:100002206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.150.245.203",nocase; classtype:trojan-activity; sid:100002207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.33.195.164",nocase; classtype:trojan-activity; sid:100002208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aatreefelling.co.za",nocase; classtype:trojan-activity; sid:100002209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abad.tv",nocase; classtype:trojan-activity; sid:100002210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abcd.bg",nocase; classtype:trojan-activity; sid:100002211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abissnet.net",nocase; classtype:trojan-activity; sid:100002212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aboveandbelow.com.au",nocase; classtype:trojan-activity; sid:100002213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absoftechworld.com",nocase; classtype:trojan-activity; sid:100002214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absupplies.co.uk",nocase; classtype:trojan-activity; sid:100002215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abyssos.eu",nocase; classtype:trojan-activity; sid:100002216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"academyshademani.com",nocase; classtype:trojan-activity; sid:100002217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acbick.com",nocase; classtype:trojan-activity; sid:100002218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"accesslinksgroup.com",nocase; classtype:trojan-activity; sid:100002219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aceeprc.com.aceeprc.com",nocase; classtype:trojan-activity; sid:100002220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acellr.co.uk",nocase; classtype:trojan-activity; sid:100002221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acteon.com.ar",nocase; classtype:trojan-activity; sid:100002222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"activecost.com.au",nocase; classtype:trojan-activity; sid:100002223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"addahealingmusic.com",nocase; classtype:trojan-activity; sid:100002224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.com",nocase; classtype:trojan-activity; sid:100002225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.memengers.com",nocase; classtype:trojan-activity; sid:100002226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.erapor.smk-alasror.net",nocase; classtype:trojan-activity; sid:100002227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.gentbcn.org",nocase; classtype:trojan-activity; sid:100002228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.grandoceanvilla.com",nocase; classtype:trojan-activity; sid:100002229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admission.kmctartskuttippuram.org",nocase; classtype:trojan-activity; sid:100002230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adventureexplorer.in",nocase; classtype:trojan-activity; sid:100002231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aeropilates.cl",nocase; classtype:trojan-activity; sid:100002232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afnan-amc.com",nocase; classtype:trojan-activity; sid:100002233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afoninblog.com",nocase; classtype:trojan-activity; sid:100002234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afrimedspecialist.com",nocase; classtype:trojan-activity; sid:100002235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agemn.co.za",nocase; classtype:trojan-activity; sid:100002236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenciadigitalwdys.com",nocase; classtype:trojan-activity; sid:100002237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenda.gmelloinformatica.com.br",nocase; classtype:trojan-activity; sid:100002238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agentt.ac.ug",nocase; classtype:trojan-activity; sid:100002239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agile8studio.com",nocase; classtype:trojan-activity; sid:100002240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aiecons.com",nocase; classtype:trojan-activity; sid:100002241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aimnaukri.com",nocase; classtype:trojan-activity; sid:100002242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aiqtest.com",nocase; classtype:trojan-activity; sid:100002243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aitorocio.com",nocase; classtype:trojan-activity; sid:100002244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajpharmaholding.com",nocase; classtype:trojan-activity; sid:100002245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajstudiollc.com",nocase; classtype:trojan-activity; sid:100002246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"akdvidyalaya.com",nocase; classtype:trojan-activity; sid:100002247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"al-wahd.com",nocase; classtype:trojan-activity; sid:100002248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alasdemariposas.org",nocase; classtype:trojan-activity; sid:100002249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alberts.diamondrelationscrm.us",nocase; classtype:trojan-activity; sid:100002250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alemelektronik.com",nocase; classtype:trojan-activity; sid:100002251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alena1971.es",nocase; classtype:trojan-activity; sid:100002252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alexdubai.com.aldiabsteel.com",nocase; classtype:trojan-activity; sid:100002253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alka.institute",nocase; classtype:trojan-activity; sid:100002254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"allforcreative.com.au",nocase; classtype:trojan-activity; sid:100002255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alltheway.travel",nocase; classtype:trojan-activity; sid:100002256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alpaylar.com.tr",nocase; classtype:trojan-activity; sid:100002257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"am-concepts.ca",nocase; classtype:trojan-activity; sid:100002258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amamontajes.com",nocase; classtype:trojan-activity; sid:100002259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarresdeamorymaestroshechiceros.com",nocase; classtype:trojan-activity; sid:100002260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarteargentina.com.ar",nocase; classtype:trojan-activity; sid:100002261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amos524.org",nocase; classtype:trojan-activity; sid:100002262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ams.alvinasschools.org.ng",nocase; classtype:trojan-activity; sid:100002263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anadelgbt.org",nocase; classtype:trojan-activity; sid:100002264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anantam.net.in",nocase; classtype:trojan-activity; sid:100002265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreelapeyre.com",nocase; classtype:trojan-activity; sid:100002266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andremaraisbeleggings.co.za",nocase; classtype:trojan-activity; sid:100002267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreonemaia.com",nocase; classtype:trojan-activity; sid:100002268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ac.ug",nocase; classtype:trojan-activity; sid:100002269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ug",nocase; classtype:trojan-activity; sid:100002270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreshconcejal.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelazgheibld.com",nocase; classtype:trojan-activity; sid:100002272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelsdetour.com",nocase; classtype:trojan-activity; sid:100002273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angloteste.bigprime.com.br",nocase; classtype:trojan-activity; sid:100002274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anhung1102.vn",nocase; classtype:trojan-activity; sid:100002275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anurontv.com",nocase; classtype:trojan-activity; sid:100002276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anysbergbiltong.co.za",nocase; classtype:trojan-activity; sid:100002277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api-ms.cobainaja.id",nocase; classtype:trojan-activity; sid:100002278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.cstdevs.com",nocase; classtype:trojan-activity; sid:100002279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.quocbao.biz",nocase; classtype:trojan-activity; sid:100002280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apoolcondo.com",nocase; classtype:trojan-activity; sid:100002281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.adsensearticle.com",nocase; classtype:trojan-activity; sid:100002282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.explicitsurveys.co.uk",nocase; classtype:trojan-activity; sid:100002283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.prerana.info",nocase; classtype:trojan-activity; sid:100002284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apps.saintsoporte.com",nocase; classtype:trojan-activity; sid:100002285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aps-scribe.com",nocase; classtype:trojan-activity; sid:100002286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aps-sv.com",nocase; classtype:trojan-activity; sid:100002287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apsusa.aero",nocase; classtype:trojan-activity; sid:100002288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"areyoulivingwell.com",nocase; classtype:trojan-activity; sid:100002289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"artedibujoyarquitectura.com",nocase; classtype:trojan-activity; sid:100002290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"arwenyapi.com",nocase; classtype:trojan-activity; sid:100002291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ask-regard.call-save.biz",nocase; classtype:trojan-activity; sid:100002292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atfile.com",nocase; classtype:trojan-activity; sid:100002293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"athenacapsg.com",nocase; classtype:trojan-activity; sid:100002294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atlanticsteelprocessing.com",nocase; classtype:trojan-activity; sid:100002295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atlasconcreteworks.com",nocase; classtype:trojan-activity; sid:100002296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"attach.66rpg.com",nocase; classtype:trojan-activity; sid:100002297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atteuqpotentialunlimited.com",nocase; classtype:trojan-activity; sid:100002298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"augustair.com",nocase; classtype:trojan-activity; sid:100002299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aulist.com",nocase; classtype:trojan-activity; sid:100002300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"automaticrefreshments.com",nocase; classtype:trojan-activity; sid:100002301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"avadhanagames.com",nocase; classtype:trojan-activity; sid:100002302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ayahuascasp.com.br",nocase; classtype:trojan-activity; sid:100002303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ayamallah.com",nocase; classtype:trojan-activity; sid:100002304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aycconsultoriaempresarial.com",nocase; classtype:trojan-activity; sid:100002305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azmeasurement.com",nocase; classtype:trojan-activity; sid:100002306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"b2b.toptanakaryakit.com.tr",nocase; classtype:trojan-activity; sid:100002307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"backgrounds.pk",nocase; classtype:trojan-activity; sid:100002308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"badeggdesign.com",nocase; classtype:trojan-activity; sid:100002309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"balealgodon.mx",nocase; classtype:trojan-activity; sid:100002310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bangkok-orchids.com",nocase; classtype:trojan-activity; sid:100002311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bangladeshunbound.com",nocase; classtype:trojan-activity; sid:100002312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bary.sz4h.com",nocase; classtype:trojan-activity; sid:100002313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bash.givemexyz.in",nocase; classtype:trojan-activity; sid:100002314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk",nocase; classtype:trojan-activity; sid:100002315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bavhome.com",nocase; classtype:trojan-activity; sid:100002316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bbia.co.uk",nocase; classtype:trojan-activity; sid:100002317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcmt.elin.co.za",nocase; classtype:trojan-activity; sid:100002318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcrg.co.za",nocase; classtype:trojan-activity; sid:100002319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bdnextrend.xyz",nocase; classtype:trojan-activity; sid:100002320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beanx88.xyz",nocase; classtype:trojan-activity; sid:100002321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bearcatpumps.com.cn",nocase; classtype:trojan-activity; sid:100002322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beautincollagen.rs",nocase; classtype:trojan-activity; sid:100002323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bekape.co.id",nocase; classtype:trojan-activity; sid:100002324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beor360.com",nocase; classtype:trojan-activity; sid:100002325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bespokeweddings.ie",nocase; classtype:trojan-activity; sid:100002326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bestcarenepal.com",nocase; classtype:trojan-activity; sid:100002327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betone.co.kr",nocase; classtype:trojan-activity; sid:100002328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betycopaints.com",nocase; classtype:trojan-activity; sid:100002329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beveragesmiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bhavaniengineering.com",nocase; classtype:trojan-activity; sid:100002331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bigmikesupplies.co.za",nocase; classtype:trojan-activity; sid:100002332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilbosaquet.ug",nocase; classtype:trojan-activity; sid:100002333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilhen.co.za",nocase; classtype:trojan-activity; sid:100002334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"billing.citywine.in",nocase; classtype:trojan-activity; sid:100002335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"billing.rahitechnosoft.com",nocase; classtype:trojan-activity; sid:100002336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"binoy.stalphonsamissionva.org",nocase; classtype:trojan-activity; sid:100002337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"biometrico.gpotecnosystems.com",nocase; classtype:trojan-activity; sid:100002338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bioskey.com",nocase; classtype:trojan-activity; sid:100002339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birdi.elin.co.za",nocase; classtype:trojan-activity; sid:100002340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birminghamlink.org",nocase; classtype:trojan-activity; sid:100002341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bizztradingbot.nl",nocase; classtype:trojan-activity; sid:100002342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bl4n3.zadns.co.za",nocase; classtype:trojan-activity; sid:100002343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.callensaxen.com",nocase; classtype:trojan-activity; sid:100002344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.cast.re",nocase; classtype:trojan-activity; sid:100002345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.difusodesign.com",nocase; classtype:trojan-activity; sid:100002346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.oyinblogs.com",nocase; classtype:trojan-activity; sid:100002347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.takbelit.com",nocase; classtype:trojan-activity; sid:100002348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bmlifestyle.co.uk",nocase; classtype:trojan-activity; sid:100002349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bnrnews.id",nocase; classtype:trojan-activity; sid:100002350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"boatpecas.com.br",nocase; classtype:trojan-activity; sid:100002351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bodenstein.co.za",nocase; classtype:trojan-activity; sid:100002352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"booksearch.com",nocase; classtype:trojan-activity; sid:100002353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bophelocare.co.za",nocase; classtype:trojan-activity; sid:100002354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bounces.mi-fs.com",nocase; classtype:trojan-activity; sid:100002355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"boutiqueofferte.com",nocase; classtype:trojan-activity; sid:100002356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bpo.correct.go.th",nocase; classtype:trojan-activity; sid:100002357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bradleyinstitute.co.za",nocase; classtype:trojan-activity; sid:100002358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brandtrust.com.pk",nocase; classtype:trojan-activity; sid:100002359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"braunfinancial.com.au",nocase; classtype:trojan-activity; sid:100002360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brendanquine.com",nocase; classtype:trojan-activity; sid:100002361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brideofmessiah.com",nocase; classtype:trojan-activity; sid:100002362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightaffiliatesales.org",nocase; classtype:trojan-activity; sid:100002363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightmega.com",nocase; classtype:trojan-activity; sid:100002364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightstarshop.com",nocase; classtype:trojan-activity; sid:100002365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"browardinsurancemiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bt2.elin.co.za",nocase; classtype:trojan-activity; sid:100002367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"btdapi.robotake.com",nocase; classtype:trojan-activity; sid:100002368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buigiaphat.com.vn",nocase; classtype:trojan-activity; sid:100002369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bulkyfoodja.com",nocase; classtype:trojan-activity; sid:100002370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bullseyemedia.in",nocase; classtype:trojan-activity; sid:100002371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"busandvanrentalmalaysia.com",nocase; classtype:trojan-activity; sid:100002372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buscascolegios.diit.cl",nocase; classtype:trojan-activity; sid:100002373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"business.softberg.ro",nocase; classtype:trojan-activity; sid:100002374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"business2.softberg.ro",nocase; classtype:trojan-activity; sid:100002375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bydspa.cl",nocase; classtype:trojan-activity; sid:100002376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c.oooooooooo.ga",nocase; classtype:trojan-activity; sid:100002377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c0140529.ferozo.com",nocase; classtype:trojan-activity; sid:100002378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"caballo.com.au",nocase; classtype:trojan-activity; sid:100002379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cacaoprojects.com",nocase; classtype:trojan-activity; sid:100002380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"calgaryautorepairservice.com",nocase; classtype:trojan-activity; sid:100002381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"callbury.in",nocase; classtype:trojan-activity; sid:100002382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"camminachetipassa.it",nocase; classtype:trojan-activity; sid:100002383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"canadianwork.cc",nocase; classtype:trojan-activity; sid:100002384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capitalgroup-kw.com",nocase; classtype:trojan-activity; sid:100002385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capoeiraventrelivre.com",nocase; classtype:trojan-activity; sid:100002386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cardilicores.com",nocase; classtype:trojan-activity; sid:100002387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cashyinvestment.org",nocase; classtype:trojan-activity; sid:100002388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"catchperch.com",nocase; classtype:trojan-activity; sid:100002389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"catchpoolshetlands.co.uk",nocase; classtype:trojan-activity; sid:100002390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cazyacustomfurniture.com",nocase; classtype:trojan-activity; sid:100002391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cbn.hypervoizd.com",nocase; classtype:trojan-activity; sid:100002392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ccauthority.net",nocase; classtype:trojan-activity; sid:100002393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdaonline.com.ar",nocase; classtype:trojan-activity; sid:100002394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cec.asso.ac-amiens.fr",nocase; classtype:trojan-activity; sid:100002395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cecra.cl",nocase; classtype:trojan-activity; sid:100002396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cellas.sk",nocase; classtype:trojan-activity; sid:100002397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cendekiabinaaksara.com",nocase; classtype:trojan-activity; sid:100002398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cfs5.tistory.com",nocase; classtype:trojan-activity; sid:100002399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ch.rmu.ac.th",nocase; classtype:trojan-activity; sid:100002400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chance5.xyz",nocase; classtype:trojan-activity; sid:100002401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"changematterscounselling.com",nocase; classtype:trojan-activity; sid:100002402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chardhamdodham.com",nocase; classtype:trojan-activity; sid:100002403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"check.askwordpressguru.com",nocase; classtype:trojan-activity; sid:100002404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chezalice.co.za",nocase; classtype:trojan-activity; sid:100002405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"childselect.com",nocase; classtype:trojan-activity; sid:100002406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile.myvnc.com",nocase; classtype:trojan-activity; sid:100002407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile80.myvnc.com",nocase; classtype:trojan-activity; sid:100002408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chipmania.it",nocase; classtype:trojan-activity; sid:100002409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cible-energy.com",nocase; classtype:trojan-activity; sid:100002410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cifeer.net",nocase; classtype:trojan-activity; sid:100002411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cirugiadenarizbucaramanga.com",nocase; classtype:trojan-activity; sid:100002412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citihits.lk",nocase; classtype:trojan-activity; sid:100002413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citssolutions.co.za",nocase; classtype:trojan-activity; sid:100002414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citycapproperty.ru",nocase; classtype:trojan-activity; sid:100002415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cityglobalgospel.com",nocase; classtype:trojan-activity; sid:100002416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"civi.istmejia.com",nocase; classtype:trojan-activity; sid:100002417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cleanbydesignllc.com",nocase; classtype:trojan-activity; sid:100002418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloud.fc.co.mz",nocase; classtype:trojan-activity; sid:100002419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cm-arquitetos.com",nocase; classtype:trojan-activity; sid:100002420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codsambal.com",nocase; classtype:trojan-activity; sid:100002421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colempaques.info",nocase; classtype:trojan-activity; sid:100002422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colorpak.pl",nocase; classtype:trojan-activity; sid:100002423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"columbia.aula-web.net",nocase; classtype:trojan-activity; sid:100002424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"community.reimclub.com",nocase; classtype:trojan-activity; sid:100002425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"competancy.indigoconsult.net",nocase; classtype:trojan-activity; sid:100002426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"conceptimagine.ro",nocase; classtype:trojan-activity; sid:100002427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"config.cqhbkjzx.com",nocase; classtype:trojan-activity; sid:100002428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"connectcapital.com.br",nocase; classtype:trojan-activity; sid:100002429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"constructoralyon.com",nocase; classtype:trojan-activity; sid:100002430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"consulateins.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"contributeindustry.com",nocase; classtype:trojan-activity; sid:100002432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"controleautomacao.com.br",nocase; classtype:trojan-activity; sid:100002433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"copelandscapes.com",nocase; classtype:trojan-activity; sid:100002434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"coulsongraphics.com",nocase; classtype:trojan-activity; sid:100002435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"count.mail.163.com.impactmedfoundation.com",nocase; classtype:trojan-activity; sid:100002436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"covid19.cyberschool.or.id",nocase; classtype:trojan-activity; sid:100002437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cpanel.shivay.net",nocase; classtype:trojan-activity; sid:100002438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cr-sq.com",nocase; classtype:trojan-activity; sid:100002439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"craftech.nxtnet.ga",nocase; classtype:trojan-activity; sid:100002440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"creationskateboards.com",nocase; classtype:trojan-activity; sid:100002441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crecerco.com",nocase; classtype:trojan-activity; sid:100002442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crittersbythebay.com",nocase; classtype:trojan-activity; sid:100002443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crm.notariavieitoyvelamazan.com",nocase; classtype:trojan-activity; sid:100002444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crmfarko.manivelasst.com",nocase; classtype:trojan-activity; sid:100002445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crmroche.manivelasst.com",nocase; classtype:trojan-activity; sid:100002446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crscorretordeimoveis.com.br",nocase; classtype:trojan-activity; sid:100002447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cse-engineer.com",nocase; classtype:trojan-activity; sid:100002448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"csnserver.com",nocase; classtype:trojan-activity; sid:100002449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cubescargoexpress.com",nocase; classtype:trojan-activity; sid:100002450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"curasoles.co.za",nocase; classtype:trojan-activity; sid:100002451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"currantmedia.com",nocase; classtype:trojan-activity; sid:100002452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cwa.mx",nocase; classtype:trojan-activity; sid:100002453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cyclomove.com",nocase; classtype:trojan-activity; sid:100002454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cynkon.kairoscs.net",nocase; classtype:trojan-activity; sid:100002455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"czsl.91756.cn",nocase; classtype:trojan-activity; sid:100002456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d.powerofwish.com",nocase; classtype:trojan-activity; sid:100002457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d9.99ddd.com",nocase; classtype:trojan-activity; sid:100002458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"da.alibuf.com",nocase; classtype:trojan-activity; sid:100002459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dagiionline.com",nocase; classtype:trojan-activity; sid:100002460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"damagedessentialtelecommunications.testmail4.repl.co",nocase; classtype:trojan-activity; sid:100002461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"danaevara.com",nocase; classtype:trojan-activity; sid:100002462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dartoonpictures.com",nocase; classtype:trojan-activity; sid:100002463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.cdevelop.org",nocase; classtype:trojan-activity; sid:100002464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.over-blog-kiwi.com",nocase; classtype:trojan-activity; sid:100002465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datapolish.com",nocase; classtype:trojan-activity; sid:100002466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dating.khokhas.co.za",nocase; classtype:trojan-activity; sid:100002467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davethompson.me.uk",nocase; classtype:trojan-activity; sid:100002468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davidmcguinness.info",nocase; classtype:trojan-activity; sid:100002469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dayspringdaisies.com",nocase; classtype:trojan-activity; sid:100002470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dd.qiyuea.cn",nocase; classtype:trojan-activity; sid:100002471; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"de.gsearch.com.de",nocase; classtype:trojan-activity; sid:100002472; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"decifrar.com.br",nocase; classtype:trojan-activity; sid:100002473; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deigratia2.elin.co.za",nocase; classtype:trojan-activity; sid:100002474; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dekovizyon.com",nocase; classtype:trojan-activity; sid:100002475; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo-cliente.mindcreative.com.br",nocase; classtype:trojan-activity; sid:100002476; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo.glassforcars.com.au",nocase; classtype:trojan-activity; sid:100002477; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo.iiitindia.in",nocase; classtype:trojan-activity; sid:100002478; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo6.hiites.com",nocase; classtype:trojan-activity; sid:100002479; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dent-estet.com",nocase; classtype:trojan-activity; sid:100002480; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dental.xiaoxiao.media",nocase; classtype:trojan-activity; sid:100002481; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dentalalliance.se",nocase; classtype:trojan-activity; sid:100002482; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"desertlandtrd.com",nocase; classtype:trojan-activity; sid:100002483; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"designerliving.co.za",nocase; classtype:trojan-activity; sid:100002484; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"desiringhands.com",nocase; classtype:trojan-activity; sid:100002485; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"despertaresi.com.br",nocase; classtype:trojan-activity; sid:100002486; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"destinymc.co.za",nocase; classtype:trojan-activity; sid:100002487; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"detorre.es",nocase; classtype:trojan-activity; sid:100002488; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev.sebpo.net",nocase; classtype:trojan-activity; sid:100002489; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev.watch-store.eu",nocase; classtype:trojan-activity; sid:100002490; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dfcf.91756.cn",nocase; classtype:trojan-activity; sid:100002491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dfsfcsfcdsfsdvcfsvcscv.com",nocase; classtype:trojan-activity; sid:100002492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"diamantenegro.mi-fs.com",nocase; classtype:trojan-activity; sid:100002493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dienmayminhhung.com",nocase; classtype:trojan-activity; sid:100002494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digilib.dianhusada.ac.id",nocase; classtype:trojan-activity; sid:100002495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digisails.org",nocase; classtype:trojan-activity; sid:100002496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"disinfection-cleaning.co.za",nocase; classtype:trojan-activity; sid:100002497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"djking.f3322.net",nocase; classtype:trojan-activity; sid:100002498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.1003b.56a.com",nocase; classtype:trojan-activity; sid:100002499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.198424.com",nocase; classtype:trojan-activity; sid:100002500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.installcdn-aws.com",nocase; classtype:trojan-activity; sid:100002501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.packetstormsecurity.net",nocase; classtype:trojan-activity; sid:100002502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.rina-roleplay.com",nocase; classtype:trojan-activity; sid:100002503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dnn.alibuf.com",nocase; classtype:trojan-activity; sid:100002504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dns.alibuf.com",nocase; classtype:trojan-activity; sid:100002505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dns.cyberium.cc",nocase; classtype:trojan-activity; sid:100002506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dockerupdate.anondns.net",nocase; classtype:trojan-activity; sid:100002507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docman.orientalservices.in",nocase; classtype:trojan-activity; sid:100002508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dodsonimaging.com",nocase; classtype:trojan-activity; sid:100002509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"doitunlimited.com",nocase; classtype:trojan-activity; sid:100002510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dokan.blueberrytec.com",nocase; classtype:trojan-activity; sid:100002511; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom-chel74.ru",nocase; classtype:trojan-activity; sid:100002512; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom.daf.free.fr",nocase; classtype:trojan-activity; sid:100002513; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"doncedyhall.com",nocase; classtype:trojan-activity; sid:100002514; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"donghobinhminh.com",nocase; classtype:trojan-activity; sid:100002515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dongphuctop.com",nocase; classtype:trojan-activity; sid:100002516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"donwnloasecury.ath.cx",nocase; classtype:trojan-activity; sid:100002517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosame.com",nocase; classtype:trojan-activity; sid:100002518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosman.pl",nocase; classtype:trojan-activity; sid:100002519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dovberger.com",nocase; classtype:trojan-activity; sid:100002520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.pcclear.com",nocase; classtype:trojan-activity; sid:100002521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.postch-de.top",nocase; classtype:trojan-activity; sid:100002522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.postch-dl.top",nocase; classtype:trojan-activity; sid:100002523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.udashi.com",nocase; classtype:trojan-activity; sid:100002524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.webbora.com",nocase; classtype:trojan-activity; sid:100002525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down1.arpun.com",nocase; classtype:trojan-activity; sid:100002526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.caihong.com",nocase; classtype:trojan-activity; sid:100002527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.doumaibiji.cn",nocase; classtype:trojan-activity; sid:100002528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.exrnybuf.cn",nocase; classtype:trojan-activity; sid:100002529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.kaobeitu.com",nocase; classtype:trojan-activity; sid:100002530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.pdf00.cn",nocase; classtype:trojan-activity; sid:100002531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.rising.com.cn",nocase; classtype:trojan-activity; sid:100002532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.skycn.com",nocase; classtype:trojan-activity; sid:100002533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.zjsyawqj.cn",nocase; classtype:trojan-activity; sid:100002534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dragonsknot.com",nocase; classtype:trojan-activity; sid:100002535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drbaby.com.sa",nocase; classtype:trojan-activity; sid:100002536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dream.pics",nocase; classtype:trojan-activity; sid:100002537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drgroup.co.za",nocase; classtype:trojan-activity; sid:100002538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drools-moved.46999.n3.nabble.com",nocase; classtype:trojan-activity; sid:100002539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drsha.innovativesolutions.mobi",nocase; classtype:trojan-activity; sid:100002540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsdisplay.co.uk",nocase; classtype:trojan-activity; sid:100002541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsenterprize.co.za",nocase; classtype:trojan-activity; sid:100002542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsspainting.com",nocase; classtype:trojan-activity; sid:100002543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"du-wizards.com",nocase; classtype:trojan-activity; sid:100002544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duanhaozhang.com",nocase; classtype:trojan-activity; sid:100002545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duque.guantanameratravel.com",nocase; classtype:trojan-activity; sid:100002546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dutapp.wisolve.co.za",nocase; classtype:trojan-activity; sid:100002547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duvalcharter.dekitout.com",nocase; classtype:trojan-activity; sid:100002548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dx.qqyewu.com",nocase; classtype:trojan-activity; sid:100002549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dzinestudio87.co.uk",nocase; classtype:trojan-activity; sid:100002550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-commerce.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100002551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e.sldov.ru",nocase; classtype:trojan-activity; sid:100002552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eandgdesign.com.ng",nocase; classtype:trojan-activity; sid:100002553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eastsheen-glaziers.co.uk",nocase; classtype:trojan-activity; sid:100002554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ebruyatkin.com",nocase; classtype:trojan-activity; sid:100002555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"edu.saicraftsman.com",nocase; classtype:trojan-activity; sid:100002556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eedo.ee",nocase; classtype:trojan-activity; sid:100002557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"efficientegroup.com",nocase; classtype:trojan-activity; sid:100002558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"elbauldenora.com",nocase; classtype:trojan-activity; sid:100002559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"emaids.co.za",nocase; classtype:trojan-activity; sid:100002560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"emaz.pk",nocase; classtype:trojan-activity; sid:100002561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"emlak.ygtsoft.com",nocase; classtype:trojan-activity; sid:100002562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"en.baoend.com",nocase; classtype:trojan-activity; sid:100002563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enc-tech.com",nocase; classtype:trojan-activity; sid:100002564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"endurotanzania.co.tz",nocase; classtype:trojan-activity; sid:100002565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ennovate.elin.co.za",nocase; classtype:trojan-activity; sid:100002566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enriquecendocomconsorcio.com.br",nocase; classtype:trojan-activity; sid:100002567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"equimination.ee",nocase; classtype:trojan-activity; sid:100002568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"erp.nanotechproautocare.com",nocase; classtype:trojan-activity; sid:100002569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"erp.zilymax.com",nocase; classtype:trojan-activity; sid:100002570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"escola.probommar.org.br",nocase; classtype:trojan-activity; sid:100002571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"esnconsultants.com",nocase; classtype:trojan-activity; sid:100002572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"essentia.org.br",nocase; classtype:trojan-activity; sid:100002573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eubanks7.com",nocase; classtype:trojan-activity; sid:100002574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"europeanzonexxi.com",nocase; classtype:trojan-activity; sid:100002575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evidencemarketing.ca",nocase; classtype:trojan-activity; sid:100002576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exilum.com",nocase; classtype:trojan-activity; sid:100002577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exitoalfaomega.co",nocase; classtype:trojan-activity; sid:100002578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"extrovertoffers.com",nocase; classtype:trojan-activity; sid:100002579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"f1sol.com",nocase; classtype:trojan-activity; sid:100002580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fahrzeugdrive.com",nocase; classtype:trojan-activity; sid:100002581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"familydentist.site",nocase; classtype:trojan-activity; sid:100002582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fc.co.mz",nocase; classtype:trojan-activity; sid:100002583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"felicienne.nl",nocase; classtype:trojan-activity; sid:100002584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.martellexpress.us",nocase; classtype:trojan-activity; sid:100002585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"filmotainment.com",nocase; classtype:trojan-activity; sid:100002586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"final.makkahkmcc.com",nocase; classtype:trojan-activity; sid:100002587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fineartgallerym.com",nocase; classtype:trojan-activity; sid:100002588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fisconline.bar",nocase; classtype:trojan-activity; sid:100002589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fix-america-now.org",nocase; classtype:trojan-activity; sid:100002590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fixauto.illumetechnology.com",nocase; classtype:trojan-activity; sid:100002591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fixturegovernment.com",nocase; classtype:trojan-activity; sid:100002592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fkd.derpcity.ru",nocase; classtype:trojan-activity; sid:100002593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flexypay.dsquaregroup.com",nocase; classtype:trojan-activity; sid:100002594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flintspin.com",nocase; classtype:trojan-activity; sid:100002595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flyingbuddhadesign.com",nocase; classtype:trojan-activity; sid:100002596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fmjplastering.co.uk",nocase; classtype:trojan-activity; sid:100002597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fms.buladde.or.ug",nocase; classtype:trojan-activity; sid:100002598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"follower.instantcashback.in",nocase; classtype:trojan-activity; sid:100002599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foothills.com.br",nocase; classtype:trojan-activity; sid:100002600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"footweardirect.elin.co.za",nocase; classtype:trojan-activity; sid:100002601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"forum.mdb.nu",nocase; classtype:trojan-activity; sid:100002602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fotoobjetivo.com",nocase; classtype:trojan-activity; sid:100002603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foxeps.com.br",nocase; classtype:trojan-activity; sid:100002604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fraud.bpcbankingtech.com",nocase; classtype:trojan-activity; sid:100002605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freecnetdownload.com",nocase; classtype:trojan-activity; sid:100002606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freisites.com.br",nocase; classtype:trojan-activity; sid:100002607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ftp.n3twork30cm.ml",nocase; classtype:trojan-activity; sid:100002608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fullelectronica.com.ar",nocase; classtype:trojan-activity; sid:100002609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"funletters.net",nocase; classtype:trojan-activity; sid:100002610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fusionfiresolutions.com",nocase; classtype:trojan-activity; sid:100002611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"futuregraphics.com.ar",nocase; classtype:trojan-activity; sid:100002612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"g.pinmonkey.xyz",nocase; classtype:trojan-activity; sid:100002613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gametwogame.com",nocase; classtype:trojan-activity; sid:100002614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garciadogshow.com",nocase; classtype:trojan-activity; sid:100002615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow.myvnc.com",nocase; classtype:trojan-activity; sid:100002616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow4.myvnc.com",nocase; classtype:trojan-activity; sid:100002617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gastoudergonny.nl",nocase; classtype:trojan-activity; sid:100002618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gbbulls.co.uk",nocase; classtype:trojan-activity; sid:100002619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gcpc.co.id.chronoscurtain.com",nocase; classtype:trojan-activity; sid:100002620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"generaldeviales.com",nocase; classtype:trojan-activity; sid:100002621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfmodd1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100002622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfold1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100002623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghettohub.co.za",nocase; classtype:trojan-activity; sid:100002624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghislain.dartois.pagesperso-orange.fr",nocase; classtype:trojan-activity; sid:100002625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giadungg7.com",nocase; classtype:trojan-activity; sid:100002626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giddos.ga",nocase; classtype:trojan-activity; sid:100002627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giteletropical.com",nocase; classtype:trojan-activity; sid:100002628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"glowinmedia.co.ke",nocase; classtype:trojan-activity; sid:100002629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmsebpl.com",nocase; classtype:trojan-activity; sid:100002630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmtransformationacademy.com",nocase; classtype:trojan-activity; sid:100002631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmvadmission.org",nocase; classtype:trojan-activity; sid:100002632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnimelf.net",nocase; classtype:trojan-activity; sid:100002633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnscrew.ro",nocase; classtype:trojan-activity; sid:100002634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gold.investforex.id",nocase; classtype:trojan-activity; sid:100002635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcake.co.id",nocase; classtype:trojan-activity; sid:100002636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com",nocase; classtype:trojan-activity; sid:100002637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com.au",nocase; classtype:trojan-activity; sid:100002638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"golden-memories-funerals.yourpageserver.com",nocase; classtype:trojan-activity; sid:100002639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldenasiacapital.com",nocase; classtype:trojan-activity; sid:100002640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldmen.in",nocase; classtype:trojan-activity; sid:100002641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gorecycle.fahadjutt.com",nocase; classtype:trojan-activity; sid:100002642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gpotecnosystems.com",nocase; classtype:trojan-activity; sid:100002643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gracejukes.com",nocase; classtype:trojan-activity; sid:100002644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"grovershospital.com",nocase; classtype:trojan-activity; sid:100002645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"grupoinmare.com",nocase; classtype:trojan-activity; sid:100002646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gruposelt.000webhostapp.com",nocase; classtype:trojan-activity; sid:100002647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gruppodomus.com.br",nocase; classtype:trojan-activity; sid:100002648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gs.monerorx.com",nocase; classtype:trojan-activity; sid:100002649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"guide-to-cell-phones.com",nocase; classtype:trojan-activity; sid:100002650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gulfac-house.com",nocase; classtype:trojan-activity; sid:100002651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gvpcdpgc.edu.in",nocase; classtype:trojan-activity; sid:100002652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"habbotips.free.fr",nocase; classtype:trojan-activity; sid:100002653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hagebakken.no",nocase; classtype:trojan-activity; sid:100002654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hamptonpartyoffive.com",nocase; classtype:trojan-activity; sid:100002655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hashmati.com",nocase; classtype:trojan-activity; sid:100002656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hassanproduct.com",nocase; classtype:trojan-activity; sid:100002657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hchfug.org",nocase; classtype:trojan-activity; sid:100002658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hd11315.com",nocase; classtype:trojan-activity; sid:100002659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hdkamera2003.hu",nocase; classtype:trojan-activity; sid:100002660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hds.sz4h.com",nocase; classtype:trojan-activity; sid:100002661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"heavymaq.cl",nocase; classtype:trojan-activity; sid:100002662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hellogorgeous.com.au",nocase; classtype:trojan-activity; sid:100002663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"help.hizuko.com",nocase; classtype:trojan-activity; sid:100002664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"herchinfitout.com.sg",nocase; classtype:trojan-activity; sid:100002665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hhaward.org",nocase; classtype:trojan-activity; sid:100002666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandroadcoc.com",nocase; classtype:trojan-activity; sid:100002667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandslasvegas.atakdev.com",nocase; classtype:trojan-activity; sid:100002668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hindi.factsriver.com",nocase; classtype:trojan-activity; sid:100002669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitpe.com",nocase; classtype:trojan-activity; sid:100002670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitstation.nl",nocase; classtype:trojan-activity; sid:100002671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hlmd.in",nocase; classtype:trojan-activity; sid:100002672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hmpmall.co.kr",nocase; classtype:trojan-activity; sid:100002673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoagietesting10.com",nocase; classtype:trojan-activity; sid:100002674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoayeuthuong-my.sharepoint.com",nocase; classtype:trojan-activity; sid:100002675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"homefindersolutions.com",nocase; classtype:trojan-activity; sid:100002676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hongluosi.com",nocase; classtype:trojan-activity; sid:100002677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hookedupboatclub.com",nocase; classtype:trojan-activity; sid:100002678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hortizwp.eastus.cloudapp.azure.com",nocase; classtype:trojan-activity; sid:100002679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostingparacolombia.com",nocase; classtype:trojan-activity; sid:100002680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostzaa.com",nocase; classtype:trojan-activity; sid:100002681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"houstonshutters.site",nocase; classtype:trojan-activity; sid:100002682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hr2019.vrcom7.com",nocase; classtype:trojan-activity; sid:100002683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hrnautica.com.br",nocase; classtype:trojan-activity; sid:100002684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hseda.com",nocase; classtype:trojan-activity; sid:100002685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"htownbars.com",nocase; classtype:trojan-activity; sid:100002686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hubtech.co.za",nocase; classtype:trojan-activity; sid:100002687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"huellacero.cl",nocase; classtype:trojan-activity; sid:100002688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hunggiang.vn",nocase; classtype:trojan-activity; sid:100002689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"husamiyahschool.com",nocase; classtype:trojan-activity; sid:100002690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iabmixx2020.rayadigital.online",nocase; classtype:trojan-activity; sid:100002691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iam313.com",nocase; classtype:trojan-activity; sid:100002692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iammdshanto.com",nocase; classtype:trojan-activity; sid:100002693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"icon.shatangmu.cn",nocase; classtype:trojan-activity; sid:100002694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idilsoft.com",nocase; classtype:trojan-activity; sid:100002695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idj.no",nocase; classtype:trojan-activity; sid:100002696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idvindia.com",nocase; classtype:trojan-activity; sid:100002697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ieclb.com.br",nocase; classtype:trojan-activity; sid:100002698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ikexpert.com",nocase; classtype:trojan-activity; sid:100002699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ilrafrica.com",nocase; classtype:trojan-activity; sid:100002700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"images.jermiau.com",nocase; classtype:trojan-activity; sid:100002701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"imbueautoworx.co.za",nocase; classtype:trojan-activity; sid:100002702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"in-tune2016.com",nocase; classtype:trojan-activity; sid:100002703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incrediblepixels.com",nocase; classtype:trojan-activity; sid:100002704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incredicole.com",nocase; classtype:trojan-activity; sid:100002705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indrasbikaner.com",nocase; classtype:trojan-activity; sid:100002706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infair.vn",nocase; classtype:trojan-activity; sid:100002707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infovator.com",nocase; classtype:trojan-activity; sid:100002708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"initialnetworks.com",nocase; classtype:trojan-activity; sid:100002709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inodesthetotaldesigners.com",nocase; classtype:trojan-activity; sid:100002710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inrajahmundry.co.in",nocase; classtype:trojan-activity; sid:100002711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"insignificantfinecore.testmail4.repl.co",nocase; classtype:trojan-activity; sid:100002712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"instantindialoan.com",nocase; classtype:trojan-activity; sid:100002713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"insupportofchildren.co.uk",nocase; classtype:trojan-activity; sid:100002714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intellectsmart.in",nocase; classtype:trojan-activity; sid:100002715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intersel-idf.org",nocase; classtype:trojan-activity; sid:100002716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intuitiveideas.com.my",nocase; classtype:trojan-activity; sid:100002717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inversiones.arrayanfinanciero.cl",nocase; classtype:trojan-activity; sid:100002718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"invest.xpcorporative.com.br",nocase; classtype:trojan-activity; sid:100002719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"investinae.com",nocase; classtype:trojan-activity; sid:100002720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ioabc.wif.com.br",nocase; classtype:trojan-activity; sid:100002721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ipmes.ma",nocase; classtype:trojan-activity; sid:100002722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iremart.es",nocase; classtype:trojan-activity; sid:100002723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iris101.co.uk",nocase; classtype:trojan-activity; sid:100002724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isaac.mikhailmotoringschool.com",nocase; classtype:trojan-activity; sid:100002725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iscamenabe.com",nocase; classtype:trojan-activity; sid:100002726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isiphephelocon.co.za",nocase; classtype:trojan-activity; sid:100002727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iso-dubai.net",nocase; classtype:trojan-activity; sid:100002728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"israrulhaq.me",nocase; classtype:trojan-activity; sid:100002729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isrorg.com",nocase; classtype:trojan-activity; sid:100002730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isso.ps",nocase; classtype:trojan-activity; sid:100002731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ist-security.com",nocase; classtype:trojan-activity; sid:100002732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"it123.ru",nocase; classtype:trojan-activity; sid:100002733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"italiandirezione.casa",nocase; classtype:trojan-activity; sid:100002734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itc-demo.softgig.co.ke",nocase; classtype:trojan-activity; sid:100002735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itelsys.ma",nocase; classtype:trojan-activity; sid:100002736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itmotasaciones.com",nocase; classtype:trojan-activity; sid:100002737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jacktech.jackindia.com",nocase; classtype:trojan-activity; sid:100002738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jaishritours.com",nocase; classtype:trojan-activity; sid:100002739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamiekaylive.com",nocase; classtype:trojan-activity; sid:100002740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamshed.pk",nocase; classtype:trojan-activity; sid:100002741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jansen-heesch.nl",nocase; classtype:trojan-activity; sid:100002742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jathra.co.uk",nocase; classtype:trojan-activity; sid:100002743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jay.diamondrelationscrm.us",nocase; classtype:trojan-activity; sid:100002744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jebs.net.au",nocase; classtype:trojan-activity; sid:100002745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jeffdahlke.com",nocase; classtype:trojan-activity; sid:100002746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jennwolfemtb.com",nocase; classtype:trojan-activity; sid:100002747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jhayesconsulting.com",nocase; classtype:trojan-activity; sid:100002748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jiaoyuzixun.cn",nocase; classtype:trojan-activity; sid:100002749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jing-da.com.tw",nocase; classtype:trojan-activity; sid:100002750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jmtc.91756.cn",nocase; classtype:trojan-activity; sid:100002751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jnanbharati.com",nocase; classtype:trojan-activity; sid:100002752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jobs.thebeessolution.com",nocase; classtype:trojan-activity; sid:100002753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"joelbonissilver.com",nocase; classtype:trojan-activity; sid:100002754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"join.cl8movement.co.za",nocase; classtype:trojan-activity; sid:100002755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"josegene.com",nocase; classtype:trojan-activity; sid:100002756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jpwoodfordco.com",nocase; classtype:trojan-activity; sid:100002757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jumpmanualjacobhiller.com",nocase; classtype:trojan-activity; sid:100002758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jupiter.toxsl.in",nocase; classtype:trojan-activity; sid:100002759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"justinscott.com.au",nocase; classtype:trojan-activity; sid:100002760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kadigital.co.uk",nocase; classtype:trojan-activity; sid:100002761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kaizenjanitorial.com",nocase; classtype:trojan-activity; sid:100002762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalawatihomes.com",nocase; classtype:trojan-activity; sid:100002763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalogirosfinance.com",nocase; classtype:trojan-activity; sid:100002764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kaptaanchapal.com",nocase; classtype:trojan-activity; sid:100002765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karer.by",nocase; classtype:trojan-activity; sid:100002766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"katanvetov.co.il",nocase; classtype:trojan-activity; sid:100002767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kensingtondriving.com",nocase; classtype:trojan-activity; sid:100002768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ketofitnessexpert.com",nocase; classtype:trojan-activity; sid:100002769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kevinjewelry.com.co",nocase; classtype:trojan-activity; sid:100002770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"keywatch.yourpageserver.com",nocase; classtype:trojan-activity; sid:100002771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kingssa.co.za",nocase; classtype:trojan-activity; sid:100002772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kjcpromo.com",nocase; classtype:trojan-activity; sid:100002773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kleinendeli.co.za",nocase; classtype:trojan-activity; sid:100002774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"korrectconceptservices.com",nocase; classtype:trojan-activity; sid:100002775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"krisbadminton.com",nocase; classtype:trojan-activity; sid:100002776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ktb.sch.id",nocase; classtype:trojan-activity; sid:100002777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kubatoglubaklava.com.tr",nocase; classtype:trojan-activity; sid:100002778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kumaralok.in",nocase; classtype:trojan-activity; sid:100002779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kwanfromhongkong.com",nocase; classtype:trojan-activity; sid:100002780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kz.sldov.ru",nocase; classtype:trojan-activity; sid:100002781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lacasadelosalebrijes.com",nocase; classtype:trojan-activity; sid:100002782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ladylabonde.com",nocase; classtype:trojan-activity; sid:100002783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lameguard.ru",nocase; classtype:trojan-activity; sid:100002784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laodongnhat.vn",nocase; classtype:trojan-activity; sid:100002785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laravel.pointersoftwares.com.br",nocase; classtype:trojan-activity; sid:100002786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lasermobilesounds.co.uk",nocase; classtype:trojan-activity; sid:100002787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laura9630fr.com",nocase; classtype:trojan-activity; sid:100002788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lauratomismith.com",nocase; classtype:trojan-activity; sid:100002789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lautarosanmiguel.com",nocase; classtype:trojan-activity; sid:100002790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lawforall.edu.lk",nocase; classtype:trojan-activity; sid:100002791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lawschoolideas.xyz",nocase; classtype:trojan-activity; sid:100002792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lceventos.net",nocase; classtype:trojan-activity; sid:100002793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ld.mediaget.com",nocase; classtype:trojan-activity; sid:100002794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ldgcorp.com",nocase; classtype:trojan-activity; sid:100002795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"learning.real-academy.net",nocase; classtype:trojan-activity; sid:100002796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leasiacherise.com",nocase; classtype:trojan-activity; sid:100002797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leczkregoslup.acelero.pl",nocase; classtype:trojan-activity; sid:100002798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"legend.nu",nocase; classtype:trojan-activity; sid:100002799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leluibuffet.com.br",nocase; classtype:trojan-activity; sid:100002800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lestesteux.ca",nocase; classtype:trojan-activity; sid:100002801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"libantravel.pl",nocase; classtype:trojan-activity; sid:100002802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.arihantmbainstitute.ac.in",nocase; classtype:trojan-activity; sid:100002803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.uib.ac.id",nocase; classtype:trojan-activity; sid:100002804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lidoraggiodisole.it",nocase; classtype:trojan-activity; sid:100002805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lifebeam.elin.co.za",nocase; classtype:trojan-activity; sid:100002806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lindnerelektroanlagen.de",nocase; classtype:trojan-activity; sid:100002807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linkintec.cn",nocase; classtype:trojan-activity; sid:100002808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"liquidaz.casa",nocase; classtype:trojan-activity; sid:100002809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"livetrack.in",nocase; classtype:trojan-activity; sid:100002810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lloydsindian.co.uk",nocase; classtype:trojan-activity; sid:100002811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lm.stagingarea.co.za",nocase; classtype:trojan-activity; sid:100002812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lmaancha.co.il",nocase; classtype:trojan-activity; sid:100002813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.cstdevs.com",nocase; classtype:trojan-activity; sid:100002814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.login2.in",nocase; classtype:trojan-activity; sid:100002815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"location-voitures.ma",nocase; classtype:trojan-activity; sid:100002816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"login.trezor.com.stockfootagesindia.com",nocase; classtype:trojan-activity; sid:100002817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"logotypfabriken.se",nocase; classtype:trojan-activity; sid:100002818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotix.de",nocase; classtype:trojan-activity; sid:100002819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotusanddragonfly.com",nocase; classtype:trojan-activity; sid:100002820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.definerisco.com",nocase; classtype:trojan-activity; sid:100002821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.difusodesign.com",nocase; classtype:trojan-activity; sid:100002822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.quama.pe",nocase; classtype:trojan-activity; sid:100002823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luckybrownie.com",nocase; classtype:trojan-activity; sid:100002824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luminouspneuma.com",nocase; classtype:trojan-activity; sid:100002825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luxomodels.com",nocase; classtype:trojan-activity; sid:100002826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m-technics.kz",nocase; classtype:trojan-activity; sid:100002827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m.estudiomoros.com.ar",nocase; classtype:trojan-activity; sid:100002828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m.mobilelocalsales.com",nocase; classtype:trojan-activity; sid:100002829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m.softsharks.com",nocase; classtype:trojan-activity; sid:100002830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"madicon.co.za",nocase; classtype:trojan-activity; sid:100002831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"magianegramagiablancayamarres.com",nocase; classtype:trojan-activity; sid:100002832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maharaniworld.com",nocase; classtype:trojan-activity; sid:100002833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.bs-eiendomme.co.za",nocase; classtype:trojan-activity; sid:100002834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.golimoapp.com",nocase; classtype:trojan-activity; sid:100002835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.jeffsono.org",nocase; classtype:trojan-activity; sid:100002836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maksi.feb.unib.ac.id",nocase; classtype:trojan-activity; sid:100002837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malaya.tv",nocase; classtype:trojan-activity; sid:100002838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malwarecoding.github.io",nocase; classtype:trojan-activity; sid:100002839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managed.oss-cn-beijing.aliyuncs.com",nocase; classtype:trojan-activity; sid:100002840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managemysalon.in",nocase; classtype:trojan-activity; sid:100002841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manantialesdelnorte.uy",nocase; classtype:trojan-activity; sid:100002842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mangalyaa.lk",nocase; classtype:trojan-activity; sid:100002843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manhtien.net",nocase; classtype:trojan-activity; sid:100002844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marcapinyo.ru",nocase; classtype:trojan-activity; sid:100002845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mario-sunjic.com",nocase; classtype:trojan-activity; sid:100002846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariobrown.net",nocase; classtype:trojan-activity; sid:100002847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariotessarollo.com",nocase; classtype:trojan-activity; sid:100002848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketinfosales.com",nocase; classtype:trojan-activity; sid:100002849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marksidfgs.ug",nocase; classtype:trojan-activity; sid:100002850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"masjidhabeebiyarazviya.mysunni.com",nocase; classtype:trojan-activity; sid:100002851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mastersofclientretention.com.au",nocase; classtype:trojan-activity; sid:100002852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"masterthedaybook.com",nocase; classtype:trojan-activity; sid:100002853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"materialescantu.com",nocase; classtype:trojan-activity; sid:100002854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"matruchhaya.co.in",nocase; classtype:trojan-activity; sid:100002855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maxiquim.cl",nocase; classtype:trojan-activity; sid:100002856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maxoprint.co.uk",nocase; classtype:trojan-activity; sid:100002857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maxtox.com.pk",nocase; classtype:trojan-activity; sid:100002858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbgrm.com",nocase; classtype:trojan-activity; sid:100002859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbjtimes.com",nocase; classtype:trojan-activity; sid:100002860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbsolutions.ge",nocase; classtype:trojan-activity; sid:100002861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbx.com.au",nocase; classtype:trojan-activity; sid:100002862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mdasa.elin.co.za",nocase; classtype:trojan-activity; sid:100002863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medevlb.org",nocase; classtype:trojan-activity; sid:100002864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"media-server.skyinternet.com.pk",nocase; classtype:trojan-activity; sid:100002865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medianews.ge",nocase; classtype:trojan-activity; sid:100002866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mediawaysnews.com",nocase; classtype:trojan-activity; sid:100002867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medistaffconsulting.com",nocase; classtype:trojan-activity; sid:100002868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meeweb.com",nocase; classtype:trojan-activity; sid:100002869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"megagynreformas.com.br",nocase; classtype:trojan-activity; sid:100002870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"megamart.afnan-amc.com",nocase; classtype:trojan-activity; sid:100002871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mehainteriors.com",nocase; classtype:trojan-activity; sid:100002872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"melissaleiteestetica.com.br",nocase; classtype:trojan-activity; sid:100002873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mercabits.com",nocase; classtype:trojan-activity; sid:100002874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"merkathink.com",nocase; classtype:trojan-activity; sid:100002875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mertlog.com",nocase; classtype:trojan-activity; sid:100002876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"metaflip.io",nocase; classtype:trojan-activity; sid:100002877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"metalin-cr.com",nocase; classtype:trojan-activity; sid:100002878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mettaanand.org",nocase; classtype:trojan-activity; sid:100002879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meuoculosnanet.com.br",nocase; classtype:trojan-activity; sid:100002880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mfevr.com",nocase; classtype:trojan-activity; sid:100002881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot.myvnc.com",nocase; classtype:trojan-activity; sid:100002882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot80.myvnc.com",nocase; classtype:trojan-activity; sid:100002883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"micalle.com.au",nocase; classtype:trojan-activity; sid:100002884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michaelphilip.com",nocase; classtype:trojan-activity; sid:100002885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michimal2.000webhostapp.com",nocase; classtype:trojan-activity; sid:100002886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microblading.mirliandias.com.br",nocase; classtype:trojan-activity; sid:100002887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microcomm-group.com",nocase; classtype:trojan-activity; sid:100002888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mikhailmotoringschool.com",nocase; classtype:trojan-activity; sid:100002889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mills-skyla30ec.com",nocase; classtype:trojan-activity; sid:100002890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mingguanwms.com",nocase; classtype:trojan-activity; sid:100002891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minuevavida.org",nocase; classtype:trojan-activity; sid:100002892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mirror.mypage.sk",nocase; classtype:trojan-activity; sid:100002893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"misterson.com",nocase; classtype:trojan-activity; sid:100002894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mkontakt.az",nocase; classtype:trojan-activity; sid:100002895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mktf.mx",nocase; classtype:trojan-activity; sid:100002896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mmdx.com",nocase; classtype:trojan-activity; sid:100002897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mmogollon.com.mx",nocase; classtype:trojan-activity; sid:100002898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mncarteam.com",nocase; classtype:trojan-activity; sid:100002899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mobile.illumetechnology.com",nocase; classtype:trojan-activity; sid:100002900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modelhouseturkey.com",nocase; classtype:trojan-activity; sid:100002901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modernmanna.org",nocase; classtype:trojan-activity; sid:100002902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"monetization.business",nocase; classtype:trojan-activity; sid:100002903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moninediy.com",nocase; classtype:trojan-activity; sid:100002904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mopai.sg",nocase; classtype:trojan-activity; sid:100002905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moreirawag.ac.ug",nocase; classtype:trojan-activity; sid:100002906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"motorcomunicacion.com",nocase; classtype:trojan-activity; sid:100002907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"msacontabil.com.br",nocase; classtype:trojan-activity; sid:100002908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mtspsmjeli.sch.id",nocase; classtype:trojan-activity; sid:100002909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mumgee.co.za",nocase; classtype:trojan-activity; sid:100002910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mundialdebienes.net",nocase; classtype:trojan-activity; sid:100002911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mundotecnologiasolar.com",nocase; classtype:trojan-activity; sid:100002912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"musaffirtours.com",nocase; classtype:trojan-activity; sid:100002913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"muzimbiti.xigubo.co.mz",nocase; classtype:trojan-activity; sid:100002914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mxpiqw.am.files.1drv.com",nocase; classtype:trojan-activity; sid:100002915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mydatebook.in",nocase; classtype:trojan-activity; sid:100002916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mymlql.com",nocase; classtype:trojan-activity; sid:100002917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myritz.vettickal.com",nocase; classtype:trojan-activity; sid:100002918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mysalons.in",nocase; classtype:trojan-activity; sid:100002919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myscape.in",nocase; classtype:trojan-activity; sid:100002920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mysura.it",nocase; classtype:trojan-activity; sid:100002921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"naeemacademy.com",nocase; classtype:trojan-activity; sid:100002922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"namnyak.co.ke",nocase; classtype:trojan-activity; sid:100002923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nap.mgsservers.com",nocase; classtype:trojan-activity; sid:100002924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"narcissisto.com",nocase; classtype:trojan-activity; sid:100002925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"narimohol.com",nocase; classtype:trojan-activity; sid:100002926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"navayurveda.in",nocase; classtype:trojan-activity; sid:100002927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nec-i.com",nocase; classtype:trojan-activity; sid:100002928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nedkellymyanmar.com",nocase; classtype:trojan-activity; sid:100002929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nelitrianggraeni.000webhostapp.com",nocase; classtype:trojan-activity; sid:100002930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nellaimasthanbiryani.com",nocase; classtype:trojan-activity; sid:100002931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nerve.untergrund.net",nocase; classtype:trojan-activity; sid:100002932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nettube.com.br",nocase; classtype:trojan-activity; sid:100002933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"networkwheels.co.za",nocase; classtype:trojan-activity; sid:100002934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neuroenergy.fahadjutt.com",nocase; classtype:trojan-activity; sid:100002935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neuromedic.com.br",nocase; classtype:trojan-activity; sid:100002936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newfuture.fr",nocase; classtype:trojan-activity; sid:100002937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newinfinitysynergy.com",nocase; classtype:trojan-activity; sid:100002938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newtreedesign.co.uk",nocase; classtype:trojan-activity; sid:100002939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newvisionopticallab.com",nocase; classtype:trojan-activity; sid:100002940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newxing.com",nocase; classtype:trojan-activity; sid:100002941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nextdigitalday.ru",nocase; classtype:trojan-activity; sid:100002942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ngdaycare.co.za",nocase; classtype:trojan-activity; sid:100002943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nguyenkekhuyen.com",nocase; classtype:trojan-activity; sid:100002944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhorangtreem.com",nocase; classtype:trojan-activity; sid:100002945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nicolas.ug",nocase; classtype:trojan-activity; sid:100002946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nidhi.iexist.in",nocase; classtype:trojan-activity; sid:100002947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nikanpolimer.ir",nocase; classtype:trojan-activity; sid:100002948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilehouse.co.ug",nocase; classtype:trojan-activity; sid:100002949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilinkeji.com",nocase; classtype:trojan-activity; sid:100002950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nimboohomes.com",nocase; classtype:trojan-activity; sid:100002951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"njtiledesigncenter.com",nocase; classtype:trojan-activity; sid:100002952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nobius.org",nocase; classtype:trojan-activity; sid:100002953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nocalnoodle.elin.co.za",nocase; classtype:trojan-activity; sid:100002954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nomadicbees.com",nocase; classtype:trojan-activity; sid:100002955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"notamuzikaletleri.com",nocase; classtype:trojan-activity; sid:100002956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ns1.the-widyantos.com",nocase; classtype:trojan-activity; sid:100002957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nsb.org.uk",nocase; classtype:trojan-activity; sid:100002958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nurmarkaz.org",nocase; classtype:trojan-activity; sid:100002959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nxtnet.ga",nocase; classtype:trojan-activity; sid:100002960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nyasabigbullets.com",nocase; classtype:trojan-activity; sid:100002961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nyeh2o.com.au",nocase; classtype:trojan-activity; sid:100002962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oakleyandfriends.co.uk",nocase; classtype:trojan-activity; sid:100002963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"obseques-conseils.com",nocase; classtype:trojan-activity; sid:100002964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oecteam.com",nocase; classtype:trojan-activity; sid:100002965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohe.ie",nocase; classtype:trojan-activity; sid:100002966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohsewgorgeous.co.uk",nocase; classtype:trojan-activity; sid:100002967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oknoplastik.sk",nocase; classtype:trojan-activity; sid:100002968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oleholeh.memangbeda.website",nocase; classtype:trojan-activity; sid:100002969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaia.org",nocase; classtype:trojan-activity; sid:100002970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaromatic.com",nocase; classtype:trojan-activity; sid:100002971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omega.az",nocase; classtype:trojan-activity; sid:100002972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oms.pappai.com",nocase; classtype:trojan-activity; sid:100002973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omscoc.pappai.com",nocase; classtype:trojan-activity; sid:100002974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedigitalcard.granvizionnecorp.com",nocase; classtype:trojan-activity; sid:100002975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.listifyapp.co",nocase; classtype:trojan-activity; sid:100002976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"online.creedglobal.in",nocase; classtype:trojan-activity; sid:100002977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onlinestatis.bar",nocase; classtype:trojan-activity; sid:100002978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"open.rawntech.com",nocase; classtype:trojan-activity; sid:100002979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"open.warehousesaas.co.uk",nocase; classtype:trojan-activity; sid:100002980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"opentoronto.org",nocase; classtype:trojan-activity; sid:100002981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"opolis.io",nocase; classtype:trojan-activity; sid:100002982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"opticaoptigral.cl",nocase; classtype:trojan-activity; sid:100002983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"optimus.com.sg",nocase; classtype:trojan-activity; sid:100002984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"order.bizpeed.com",nocase; classtype:trojan-activity; sid:100002985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orientgatewayltd.com",nocase; classtype:trojan-activity; sid:100002986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orion445.com",nocase; classtype:trojan-activity; sid:100002987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oserve.pk",nocase; classtype:trojan-activity; sid:100002988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ot.weenets.com",nocase; classtype:trojan-activity; sid:100002989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"otolithenrichment.fahadjutt.com",nocase; classtype:trojan-activity; sid:100002990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"outletdosaquecedores.com.br",nocase; classtype:trojan-activity; sid:100002991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ozemag.com",nocase; classtype:trojan-activity; sid:100002992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p1.lingpao8.com",nocase; classtype:trojan-activity; sid:100002993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p3.zbjimg.com",nocase; classtype:trojan-activity; sid:100002994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p6.zbjimg.com",nocase; classtype:trojan-activity; sid:100002995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pablobrothel.com.ar",nocase; classtype:trojan-activity; sid:100002996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacificgroup.ws",nocase; classtype:trojan-activity; sid:100002997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacwebdesigns.com",nocase; classtype:trojan-activity; sid:100002998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pagos.krayem.com.mx",nocase; classtype:trojan-activity; sid:100002999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"palbas.cl",nocase; classtype:trojan-activity; sid:100003000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"palochusvet.szm.com",nocase; classtype:trojan-activity; sid:100003001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pamperpartypros.co.za",nocase; classtype:trojan-activity; sid:100003002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parallel.rockvideos.at",nocase; classtype:trojan-activity; sid:100003003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parejasfelices.mi-fs.com",nocase; classtype:trojan-activity; sid:100003004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parkhussion.com",nocase; classtype:trojan-activity; sid:100003005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"partharaj.me",nocase; classtype:trojan-activity; sid:100003006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"partsapp.com.br",nocase; classtype:trojan-activity; sid:100003007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastorpaulocosta.com",nocase; classtype:trojan-activity; sid:100003008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.51lg.com",nocase; classtype:trojan-activity; sid:100003009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.99ddd.com",nocase; classtype:trojan-activity; sid:100003010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch3.99ddd.com",nocase; classtype:trojan-activity; sid:100003011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paths.elin.co.za",nocase; classtype:trojan-activity; sid:100003012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patriotsupremehemp.com",nocase; classtype:trojan-activity; sid:100003013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paulmercier.biz",nocase; classtype:trojan-activity; sid:100003014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payerrealty.com",nocase; classtype:trojan-activity; sid:100003015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payments.atifsiddiqui.me",nocase; classtype:trojan-activity; sid:100003016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pcsoori.com",nocase; classtype:trojan-activity; sid:100003017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pd.oceaniarp.net",nocase; classtype:trojan-activity; sid:100003018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pemdodo.com",nocase; classtype:trojan-activity; sid:100003019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perfumeriamontes.es",nocase; classtype:trojan-activity; sid:100003020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"periodiche.bar",nocase; classtype:trojan-activity; sid:100003021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpus.onlineman7-jombang.sch.id",nocase; classtype:trojan-activity; sid:100003022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpustekim.untirta.ac.id",nocase; classtype:trojan-activity; sid:100003023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pestoclean.co.uk",nocase; classtype:trojan-activity; sid:100003024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"petercollie.com",nocase; classtype:trojan-activity; sid:100003025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"petroindia.co.in",nocase; classtype:trojan-activity; sid:100003026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ph4s.ru",nocase; classtype:trojan-activity; sid:100003027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phasdesign.com",nocase; classtype:trojan-activity; sid:100003028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phenhuong.sanpham.online",nocase; classtype:trojan-activity; sid:100003029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phittc.com",nocase; classtype:trojan-activity; sid:100003030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"photo360.kubooking.com",nocase; classtype:trojan-activity; sid:100003031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pink99.com",nocase; classtype:trojan-activity; sid:100003032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pinkpaprika.co.uk",nocase; classtype:trojan-activity; sid:100003033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"plasfan.ind.br",nocase; classtype:trojan-activity; sid:100003034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"platinumherbal.com",nocase; classtype:trojan-activity; sid:100003035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"playground2.grupoaliadasca.com",nocase; classtype:trojan-activity; sid:100003036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pmglance.startwriteup.com",nocase; classtype:trojan-activity; sid:100003037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pointactionsg.com",nocase; classtype:trojan-activity; sid:100003038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pokojewewladyslawowie.pl",nocase; classtype:trojan-activity; sid:100003039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pole.com.vc",nocase; classtype:trojan-activity; sid:100003040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ponchokhana.com",nocase; classtype:trojan-activity; sid:100003041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pool.phxdir.com",nocase; classtype:trojan-activity; sid:100003042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pooltablemoversdenver.net",nocase; classtype:trojan-activity; sid:100003043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"portal.premiumpunch.com",nocase; classtype:trojan-activity; sid:100003044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"posmicrosystems.com",nocase; classtype:trojan-activity; sid:100003045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"poulman.panagiotopoulos-tours.gr",nocase; classtype:trojan-activity; sid:100003046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ppdb.smk-ciptaskill.sch.id",nocase; classtype:trojan-activity; sid:100003047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestasicash.com.ar",nocase; classtype:trojan-activity; sid:100003048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestigehomeautomation.net",nocase; classtype:trojan-activity; sid:100003049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"preview2.behalen.com",nocase; classtype:trojan-activity; sid:100003050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prishaartcreations.com",nocase; classtype:trojan-activity; sid:100003051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prismaxis.com",nocase; classtype:trojan-activity; sid:100003052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"production.sparshims.com",nocase; classtype:trojan-activity; sid:100003053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"programaoperadoronline.com.br",nocase; classtype:trojan-activity; sid:100003054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"project.exquitec.com",nocase; classtype:trojan-activity; sid:100003055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promotapp.com",nocase; classtype:trojan-activity; sid:100003056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promotoradescomplica.com.br",nocase; classtype:trojan-activity; sid:100003057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promoversdubai.com",nocase; classtype:trojan-activity; sid:100003058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq.elin.co.za",nocase; classtype:trojan-activity; sid:100003059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq2.elin.co.za",nocase; classtype:trojan-activity; sid:100003060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosoc.nl",nocase; classtype:trojan-activity; sid:100003061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosupport.cl",nocase; classtype:trojan-activity; sid:100003062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosyarmakassar.com",nocase; classtype:trojan-activity; sid:100003063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"provence.elin.co.za",nocase; classtype:trojan-activity; sid:100003064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prueba.danielluza.com",nocase; classtype:trojan-activity; sid:100003065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pujashoppe.in",nocase; classtype:trojan-activity; sid:100003066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punchdialogues.com",nocase; classtype:trojan-activity; sid:100003067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punjabdevelopersassociation.com.pk",nocase; classtype:trojan-activity; sid:100003068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pvcprinting.co.uk",nocase; classtype:trojan-activity; sid:100003069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qadir.tickfa.ir",nocase; classtype:trojan-activity; sid:100003070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qatarglobalconsulting.com",nocase; classtype:trojan-activity; sid:100003071; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qmsled.com",nocase; classtype:trojan-activity; sid:100003072; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quartier-midi.be",nocase; classtype:trojan-activity; sid:100003073; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"querocar.com",nocase; classtype:trojan-activity; sid:100003074; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rachmat-assuhaimi.my.id",nocase; classtype:trojan-activity; sid:100003075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"radioafifense.deploys.live",nocase; classtype:trojan-activity; sid:100003076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rainbowisp.info",nocase; classtype:trojan-activity; sid:100003077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rajeshtailang.com",nocase; classtype:trojan-activity; sid:100003078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rakeshkhatri.in",nocase; classtype:trojan-activity; sid:100003079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raodigitalmedia.com",nocase; classtype:trojan-activity; sid:100003080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raquelhelena.com.br",nocase; classtype:trojan-activity; sid:100003081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rarlabarchiver.ac",nocase; classtype:trojan-activity; sid:100003082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rasadbar.ir",nocase; classtype:trojan-activity; sid:100003083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rashika.ascarvalho.co.za",nocase; classtype:trojan-activity; sid:100003084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ratemyfenancialadvisor.com",nocase; classtype:trojan-activity; sid:100003085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ravenproductionsltd.com",nocase; classtype:trojan-activity; sid:100003086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rc.ixiaoyang.cn",nocase; classtype:trojan-activity; sid:100003087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rcmesilva.charbelsales.com.br",nocase; classtype:trojan-activity; sid:100003088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reacredit.com.br",nocase; classtype:trojan-activity; sid:100003089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"readymmade.com",nocase; classtype:trojan-activity; sid:100003090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"recyclethesurplus.com",nocase; classtype:trojan-activity; sid:100003091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"redbats.co.in",nocase; classtype:trojan-activity; sid:100003092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"redchillicrackers.com",nocase; classtype:trojan-activity; sid:100003093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reifenquick.de",nocase; classtype:trojan-activity; sid:100003094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"relaxindulge.co.nz",nocase; classtype:trojan-activity; sid:100003095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"renehavis.com.ua",nocase; classtype:trojan-activity; sid:100003096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"repatriacioncolombia.com",nocase; classtype:trojan-activity; sid:100003097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.uf1.cn",nocase; classtype:trojan-activity; sid:100003098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reseller.digimitra.in",nocase; classtype:trojan-activity; sid:100003099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reseller.itechbrasil.com",nocase; classtype:trojan-activity; sid:100003100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"resuco.net",nocase; classtype:trojan-activity; sid:100003101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rezkabum.ru",nocase; classtype:trojan-activity; sid:100003102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rhema.com.sg",nocase; classtype:trojan-activity; sid:100003103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"richmondminerals.co.zm",nocase; classtype:trojan-activity; sid:100003104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinaefoundation.org.za",nocase; classtype:trojan-activity; sid:100003105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinkaisystem-ht.com",nocase; classtype:trojan-activity; sid:100003106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"riverfox.co.za",nocase; classtype:trojan-activity; sid:100003107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkcable.co.in",nocase; classtype:trojan-activity; sid:100003108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkverify.securestudies.com",nocase; classtype:trojan-activity; sid:100003109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertmcardle.com",nocase; classtype:trojan-activity; sid:100003110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertsinclair.net",nocase; classtype:trojan-activity; sid:100003111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ronnietucker.co.uk",nocase; classtype:trojan-activity; sid:100003112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roomsvc.servegate.kr",nocase; classtype:trojan-activity; sid:100003113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roshnijewellery.com",nocase; classtype:trojan-activity; sid:100003114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rsgym.net",nocase; classtype:trojan-activity; sid:100003115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubazar.pro",nocase; classtype:trojan-activity; sid:100003116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubycityvietnam.com",nocase; classtype:trojan-activity; sid:100003117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruisgood.ru",nocase; classtype:trojan-activity; sid:100003118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruwadalkuwait.com",nocase; classtype:trojan-activity; sid:100003119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rydchile.cl",nocase; classtype:trojan-activity; sid:100003120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.thechinesemuslim.com",nocase; classtype:trojan-activity; sid:100003121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sac2.11xii.com",nocase; classtype:trojan-activity; sid:100003122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sacredscentsonline.com",nocase; classtype:trojan-activity; sid:100003123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sadmahfuneralservices.co.za",nocase; classtype:trojan-activity; sid:100003124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safcol-colors.com",nocase; classtype:trojan-activity; sid:100003125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safehubsecurity.ca",nocase; classtype:trojan-activity; sid:100003126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safety.nanotechproautocare.com",nocase; classtype:trojan-activity; sid:100003127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sahathaikasetpan.com",nocase; classtype:trojan-activity; sid:100003128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sainzim.co.za",nocase; classtype:trojan-activity; sid:100003129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"saisoftwareinc.com",nocase; classtype:trojan-activity; sid:100003130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"salecorner.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"salonsaifa.com",nocase; classtype:trojan-activity; sid:100003132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"samriddhijyotish.com",nocase; classtype:trojan-activity; sid:100003133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sandovalgraphics.com",nocase; classtype:trojan-activity; sid:100003134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"santyago.org",nocase; classtype:trojan-activity; sid:100003135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sasystemsuk.com",nocase; classtype:trojan-activity; sid:100003136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scaladevelopments.scaladevco.com",nocase; classtype:trojan-activity; sid:100003137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scarfaceindustries.com",nocase; classtype:trojan-activity; sid:100003138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scglobal.co.th",nocase; classtype:trojan-activity; sid:100003139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schalke04rss.de",nocase; classtype:trojan-activity; sid:100003140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scheff.com",nocase; classtype:trojan-activity; sid:100003141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schoolbustracker.softgig.co.ke",nocase; classtype:trojan-activity; sid:100003142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sculetus.nl",nocase; classtype:trojan-activity; sid:100003143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"secure-doc-reader.com",nocase; classtype:trojan-activity; sid:100003144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"segalsmetals.elin.co.za",nocase; classtype:trojan-activity; sid:100003145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sellmyphonela.com",nocase; classtype:trojan-activity; sid:100003146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"selltechtoday.com",nocase; classtype:trojan-activity; sid:100003147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"senbiaojita.com",nocase; classtype:trojan-activity; sid:100003148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sentierodelviandante.ml",nocase; classtype:trojan-activity; sid:100003149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"serendibsourcing.com",nocase; classtype:trojan-activity; sid:100003150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sericaasia.com",nocase; classtype:trojan-activity; sid:100003151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd.myvnc.com",nocase; classtype:trojan-activity; sid:100003152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd80.myvnc.com",nocase; classtype:trojan-activity; sid:100003153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"serviciovirtual.com.ar",nocase; classtype:trojan-activity; sid:100003154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sexologistpakistan.net",nocase; classtype:trojan-activity; sid:100003155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"seyranikenger.com.tr",nocase; classtype:trojan-activity; sid:100003156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sgb.ac.ke",nocase; classtype:trojan-activity; sid:100003157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sgessy.com.br",nocase; classtype:trojan-activity; sid:100003158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shaheentbfoundation.com",nocase; classtype:trojan-activity; sid:100003159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shahikhana.cstdevs.com",nocase; classtype:trojan-activity; sid:100003160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shahu66.com",nocase; classtype:trojan-activity; sid:100003161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharkrigs.com",nocase; classtype:trojan-activity; sid:100003162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharpelevators.in",nocase; classtype:trojan-activity; sid:100003163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shembefoundation.com",nocase; classtype:trojan-activity; sid:100003164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shivakunwar.com.np",nocase; classtype:trojan-activity; sid:100003165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shoblasaathitrust.org",nocase; classtype:trojan-activity; sid:100003166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shooka-co.com",nocase; classtype:trojan-activity; sid:100003167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shop.goldspot.agency",nocase; classtype:trojan-activity; sid:100003168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shopsofe.com",nocase; classtype:trojan-activity; sid:100003169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shrinikelectrical.co.za",nocase; classtype:trojan-activity; sid:100003170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sibernetix.fr",nocase; classtype:trojan-activity; sid:100003171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sige.brisainformatica.com.br",nocase; classtype:trojan-activity; sid:100003172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"signatureads.co.in",nocase; classtype:trojan-activity; sid:100003173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siili.net",nocase; classtype:trojan-activity; sid:100003174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simoneporzi.it",nocase; classtype:trojan-activity; sid:100003175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simorsint.com",nocase; classtype:trojan-activity; sid:100003176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simplithy.co.uk",nocase; classtype:trojan-activity; sid:100003177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindicato1ucm.cl",nocase; classtype:trojan-activity; sid:100003178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindpol.tiejuris.com.br",nocase; classtype:trojan-activity; sid:100003179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sinergidwireka.com",nocase; classtype:trojan-activity; sid:100003180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sipahielektrik.com",nocase; classtype:trojan-activity; sid:100003181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sistelligent.com",nocase; classtype:trojan-activity; sid:100003182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skare.net",nocase; classtype:trojan-activity; sid:100003183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyflyfares.com",nocase; classtype:trojan-activity; sid:100003184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyscan.com",nocase; classtype:trojan-activity; sid:100003185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smarthouseforum.ru",nocase; classtype:trojan-activity; sid:100003186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smartzedu.com",nocase; classtype:trojan-activity; sid:100003187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smokesolutionindia.com",nocase; classtype:trojan-activity; sid:100003188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smritiphotography.in",nocase; classtype:trojan-activity; sid:100003189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sobariko.com",nocase; classtype:trojan-activity; sid:100003190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sobethuacademy.com",nocase; classtype:trojan-activity; sid:100003191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.110route.com",nocase; classtype:trojan-activity; sid:100003192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.officelabo.net",nocase; classtype:trojan-activity; sid:100003193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"softanis.net",nocase; classtype:trojan-activity; sid:100003194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sogecoenergy.com",nocase; classtype:trojan-activity; sid:100003195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sohs.conceptechs.info",nocase; classtype:trojan-activity; sid:100003196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"solar.amazingtribe.lk",nocase; classtype:trojan-activity; sid:100003197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somcorbera.cat",nocase; classtype:trojan-activity; sid:100003198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somir.com.mx",nocase; classtype:trojan-activity; sid:100003199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soralapps.com",nocase; classtype:trojan-activity; sid:100003200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sota-france.fr",nocase; classtype:trojan-activity; sid:100003201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"space.proactint.org",nocase; classtype:trojan-activity; sid:100003202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spaceframe.mobi.space-frame.co.za",nocase; classtype:trojan-activity; sid:100003203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"special-key.cf",nocase; classtype:trojan-activity; sid:100003204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spent.com.pl",nocase; classtype:trojan-activity; sid:100003205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spetsesyachtcharter.gr",nocase; classtype:trojan-activity; sid:100003206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spiritualroot.org",nocase; classtype:trojan-activity; sid:100003207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spititourism.com",nocase; classtype:trojan-activity; sid:100003208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spittinfire.com",nocase; classtype:trojan-activity; sid:100003209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sports-net.de",nocase; classtype:trojan-activity; sid:100003210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"src1.minibai.com",nocase; classtype:trojan-activity; sid:100003211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sreenivasapaintingworks.com",nocase; classtype:trojan-activity; sid:100003212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sriglobalit.com",nocase; classtype:trojan-activity; sid:100003213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"srilankamovies.com",nocase; classtype:trojan-activity; sid:100003214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"srvmanos.no-ip.info",nocase; classtype:trojan-activity; sid:100003215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ss.monita.co.id",nocase; classtype:trojan-activity; sid:100003216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"st.devcodin.com",nocase; classtype:trojan-activity; sid:100003217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"staging.apparelpunch.com",nocase; classtype:trojan-activity; sid:100003218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"starcountry.net",nocase; classtype:trojan-activity; sid:100003219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"static.3001.net",nocase; classtype:trojan-activity; sid:100003220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stiau.iuc.ac",nocase; classtype:trojan-activity; sid:100003221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sticker.jewsjuice.com",nocase; classtype:trojan-activity; sid:100003222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stiepancasetia.ac.id",nocase; classtype:trojan-activity; sid:100003223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stlukesohag.com",nocase; classtype:trojan-activity; sid:100003224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"store.ericalgarin.com",nocase; classtype:trojan-activity; sid:100003225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stott-thompson.co.uk",nocase; classtype:trojan-activity; sid:100003226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stratexec.co.za",nocase; classtype:trojan-activity; sid:100003227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"suboldesign.com",nocase; classtype:trojan-activity; sid:100003228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sumerians.org",nocase; classtype:trojan-activity; sid:100003229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunaryem.com.tr",nocase; classtype:trojan-activity; sid:100003230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunbrero.com.au",nocase; classtype:trojan-activity; sid:100003231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunmarkholidays.com",nocase; classtype:trojan-activity; sid:100003232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"supermercadostia.com",nocase; classtype:trojan-activity; sid:100003233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support-4-free.com",nocase; classtype:trojan-activity; sid:100003234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support.clz.kr",nocase; classtype:trojan-activity; sid:100003235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"supportit.online",nocase; classtype:trojan-activity; sid:100003236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sw.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweaty.dk",nocase; classtype:trojan-activity; sid:100003238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweet-diet.com",nocase; classtype:trojan-activity; sid:100003239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swiftlogisticseg.com",nocase; classtype:trojan-activity; sid:100003240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swwbia.com",nocase; classtype:trojan-activity; sid:100003241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"syracusecoffee.com",nocase; classtype:trojan-activity; sid:100003242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sytraders.co",nocase; classtype:trojan-activity; sid:100003243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"t.honker.info",nocase; classtype:trojan-activity; sid:100003244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"t.netcatkit.com",nocase; classtype:trojan-activity; sid:100003245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tacticohosting.com",nocase; classtype:trojan-activity; sid:100003246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tadoo.ca",nocase; classtype:trojan-activity; sid:100003247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tafsantoursandtravels.com",nocase; classtype:trojan-activity; sid:100003248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tajushariya.com",nocase; classtype:trojan-activity; sid:100003249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tallyinvoicecustomization.com",nocase; classtype:trojan-activity; sid:100003250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taltus.co.uk",nocase; classtype:trojan-activity; sid:100003251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tapalkoedacoffee.com",nocase; classtype:trojan-activity; sid:100003252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tarravalleyfoods.com.au",nocase; classtype:trojan-activity; sid:100003253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taurus.ug",nocase; classtype:trojan-activity; sid:100003254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tavo.cl",nocase; classtype:trojan-activity; sid:100003255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taxicabsrilanka.com",nocase; classtype:trojan-activity; sid:100003256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tc.snpsresidential.com",nocase; classtype:trojan-activity; sid:100003257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tcy.198424.com",nocase; classtype:trojan-activity; sid:100003258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tdsp.yngw518.com",nocase; classtype:trojan-activity; sid:100003259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tech332.synology.me",nocase; classtype:trojan-activity; sid:100003260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"techgms.com",nocase; classtype:trojan-activity; sid:100003261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teduae.com",nocase; classtype:trojan-activity; sid:100003262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teleargentina.com",nocase; classtype:trojan-activity; sid:100003263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"telescopelms.com",nocase; classtype:trojan-activity; sid:100003264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tencoconsulting.com",nocase; classtype:trojan-activity; sid:100003265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teneth.co.za",nocase; classtype:trojan-activity; sid:100003266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tentandoserfitness.000webhostapp.com",nocase; classtype:trojan-activity; sid:100003267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tessrobins.com",nocase; classtype:trojan-activity; sid:100003268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.adventser.com",nocase; classtype:trojan-activity; sid:100003269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.letraele.es",nocase; classtype:trojan-activity; sid:100003270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.lubrico.in",nocase; classtype:trojan-activity; sid:100003271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.typoten.com",nocase; classtype:trojan-activity; sid:100003272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.wanepghana.org",nocase; classtype:trojan-activity; sid:100003273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.asistencia247.com",nocase; classtype:trojan-activity; sid:100003274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.milenial.id",nocase; classtype:trojan-activity; sid:100003275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.tenplusone.my",nocase; classtype:trojan-activity; sid:100003276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.basis-web.com",nocase; classtype:trojan-activity; sid:100003277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.marrenconstruction.ie",nocase; classtype:trojan-activity; sid:100003278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.clickitsolutionsmw.com",nocase; classtype:trojan-activity; sid:100003279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.thinkingcorp.in",nocase; classtype:trojan-activity; sid:100003280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testnew.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testuat.itmoregistry.com",nocase; classtype:trojan-activity; sid:100003282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teteaffiche.stephanebillon.com",nocase; classtype:trojan-activity; sid:100003283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tewoerd.eu",nocase; classtype:trojan-activity; sid:100003284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"textile.softberg.ro",nocase; classtype:trojan-activity; sid:100003285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tharringtonsponsorship.com",nocase; classtype:trojan-activity; sid:100003286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theatretalkies.in",nocase; classtype:trojan-activity; sid:100003287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecleaningladiespdx.com",nocase; classtype:trojan-activity; sid:100003288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecreativecafe.co.uk",nocase; classtype:trojan-activity; sid:100003289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thedesertship.com",nocase; classtype:trojan-activity; sid:100003290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thediasporianexperience.com",nocase; classtype:trojan-activity; sid:100003291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thefirmlawgroup.com.au",nocase; classtype:trojan-activity; sid:100003292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thefuturelife.in",nocase; classtype:trojan-activity; sid:100003293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thehighlightinterior.com",nocase; classtype:trojan-activity; sid:100003294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thekassia.co.uk",nocase; classtype:trojan-activity; sid:100003295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"themansionkasauli.com",nocase; classtype:trojan-activity; sid:100003296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theprofinn.com",nocase; classtype:trojan-activity; sid:100003297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thesummitpc.net",nocase; classtype:trojan-activity; sid:100003298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theurbantutors.com",nocase; classtype:trojan-activity; sid:100003299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thirdstringcalifornia.com",nocase; classtype:trojan-activity; sid:100003300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thosewebbs.com",nocase; classtype:trojan-activity; sid:100003301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thriveink.com",nocase; classtype:trojan-activity; sid:100003302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tianangdep.com",nocase; classtype:trojan-activity; sid:100003303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickfoods.tickme.lk",nocase; classtype:trojan-activity; sid:100003304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tienda.ventadigital.com.ar",nocase; classtype:trojan-activity; sid:100003305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"timamollo.co.za",nocase; classtype:trojan-activity; sid:100003306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"timegonebuy.com",nocase; classtype:trojan-activity; sid:100003307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tksb.net",nocase; classtype:trojan-activity; sid:100003308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tlcc.com.gt",nocase; classtype:trojan-activity; sid:100003309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"todoapp.cstdevs.com",nocase; classtype:trojan-activity; sid:100003310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"todocontodo.com.mx",nocase; classtype:trojan-activity; sid:100003311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonydong.com",nocase; classtype:trojan-activity; sid:100003312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonystram.com",nocase; classtype:trojan-activity; sid:100003313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonyzone.com",nocase; classtype:trojan-activity; sid:100003314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tooba.tenplusone.my",nocase; classtype:trojan-activity; sid:100003315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tools.reimclub.com",nocase; classtype:trojan-activity; sid:100003316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topcell9.com",nocase; classtype:trojan-activity; sid:100003317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toplevel.com.br",nocase; classtype:trojan-activity; sid:100003318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topmask.co.za",nocase; classtype:trojan-activity; sid:100003319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"torresquinterocorp.com",nocase; classtype:trojan-activity; sid:100003320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toyotacollege.ac.th",nocase; classtype:trojan-activity; sid:100003321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpef.lsoftdemo.com",nocase; classtype:trojan-activity; sid:100003322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpke.hu",nocase; classtype:trojan-activity; sid:100003323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"translaterjemah.com",nocase; classtype:trojan-activity; sid:100003324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"travelwithmanta.co.za",nocase; classtype:trojan-activity; sid:100003325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trendyshoes.co.za",nocase; classtype:trojan-activity; sid:100003326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trezors.io.mahlongwa.com",nocase; classtype:trojan-activity; sid:100003327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trimestre.bar",nocase; classtype:trojan-activity; sid:100003328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"triplonet.com.br",nocase; classtype:trojan-activity; sid:100003329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"troki.com.co",nocase; classtype:trojan-activity; sid:100003330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tropics.codeleek.net",nocase; classtype:trojan-activity; sid:100003331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trudelfavreau.com",nocase; classtype:trojan-activity; sid:100003332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsd.jxwan.com",nocase; classtype:trojan-activity; sid:100003333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tulli.info",nocase; classtype:trojan-activity; sid:100003334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tupperware.michaelroberge.ca",nocase; classtype:trojan-activity; sid:100003335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"turanggaresources.com",nocase; classtype:trojan-activity; sid:100003336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"txtdust.com",nocase; classtype:trojan-activity; sid:100003337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uat.indianfilmzone.com",nocase; classtype:trojan-activity; sid:100003338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ublretailerdemo.cstdevs.com",nocase; classtype:trojan-activity; sid:100003339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uc-56.ru",nocase; classtype:trojan-activity; sid:100003340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uisusa.uisusa.com",nocase; classtype:trojan-activity; sid:100003341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ultimate-24.de",nocase; classtype:trojan-activity; sid:100003342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"umwelt-kirchhof.de",nocase; classtype:trojan-activity; sid:100003343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unicorpbrunei.com",nocase; classtype:trojan-activity; sid:100003344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uniengrisb.com",nocase; classtype:trojan-activity; sid:100003345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unisoftcc.com",nocase; classtype:trojan-activity; sid:100003346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unyazitelecom.com",nocase; classtype:trojan-activity; sid:100003347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"upcbpta.com",nocase; classtype:trojan-activity; sid:100003348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"urbantrapfest.cl",nocase; classtype:trojan-activity; sid:100003349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"usamyforever.azureedge.net",nocase; classtype:trojan-activity; sid:100003350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"used-jeans.fr",nocase; classtype:trojan-activity; sid:100003351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"useformoney.000webhostapp.com",nocase; classtype:trojan-activity; sid:100003352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"usmadetshirts.com",nocase; classtype:trojan-activity; sid:100003353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uss.ac.th",nocase; classtype:trojan-activity; sid:100003354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uzzepay.com.br",nocase; classtype:trojan-activity; sid:100003355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vanzare.cabanabrazi2.ro",nocase; classtype:trojan-activity; sid:100003356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vbcargo.hu",nocase; classtype:trojan-activity; sid:100003357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vcah.co.uk",nocase; classtype:trojan-activity; sid:100003358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vectarts.com",nocase; classtype:trojan-activity; sid:100003359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vegadelcasero.cl",nocase; classtype:trojan-activity; sid:100003360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"velma-harber30ku.com",nocase; classtype:trojan-activity; sid:100003361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vendas.lidiacarmeli.com.br",nocase; classtype:trojan-activity; sid:100003362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"versualstudio.com",nocase; classtype:trojan-activity; sid:100003363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"veterinariadrpopui.com",nocase; classtype:trojan-activity; sid:100003364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vfocus.net",nocase; classtype:trojan-activity; sid:100003365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vienen.gblix.srv.br",nocase; classtype:trojan-activity; sid:100003366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vilaart.rs",nocase; classtype:trojan-activity; sid:100003367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villamarand.com",nocase; classtype:trojan-activity; sid:100003368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villatera.com",nocase; classtype:trojan-activity; sid:100003369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"violinstop.com",nocase; classtype:trojan-activity; sid:100003370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"virtuleverage.com",nocase; classtype:trojan-activity; sid:100003371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visions.alnisamart.com",nocase; classtype:trojan-activity; sid:100003372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visualhome.cl",nocase; classtype:trojan-activity; sid:100003373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vitoriamodaintima.com.br",nocase; classtype:trojan-activity; sid:100003374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vivationdesign.com",nocase; classtype:trojan-activity; sid:100003375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"viveirodoiscorregos.com.br",nocase; classtype:trojan-activity; sid:100003376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vksales.com",nocase; classtype:trojan-activity; sid:100003377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vocalterra.com",nocase; classtype:trojan-activity; sid:100003378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vokasi.ub.ac.id",nocase; classtype:trojan-activity; sid:100003379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vologroup.com.br",nocase; classtype:trojan-activity; sid:100003380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"voteyouramerica.dekitout.com",nocase; classtype:trojan-activity; sid:100003381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vpinversiones.cl",nocase; classtype:trojan-activity; sid:100003382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vpts.co.za",nocase; classtype:trojan-activity; sid:100003383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vstsample.com",nocase; classtype:trojan-activity; sid:100003384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vtube.fadlymotivator.com",nocase; classtype:trojan-activity; sid:100003385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vvsskmodinationalschool.com",nocase; classtype:trojan-activity; sid:100003386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu",nocase; classtype:trojan-activity; sid:100003387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepliberia.org",nocase; classtype:trojan-activity; sid:100003388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepniger.org",nocase; classtype:trojan-activity; sid:100003389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weareactum.com",nocase; classtype:trojan-activity; sid:100003390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.eng.ubu.ac.th",nocase; classtype:trojan-activity; sid:100003391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.geetle.ga",nocase; classtype:trojan-activity; sid:100003392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.geomegasoft.net",nocase; classtype:trojan-activity; sid:100003393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.newinnovationtechnology.com",nocase; classtype:trojan-activity; sid:100003394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.smarts-works.com",nocase; classtype:trojan-activity; sid:100003395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.thebeessolution.com",nocase; classtype:trojan-activity; sid:100003396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webgis.perumdasolo.com",nocase; classtype:trojan-activity; sid:100003397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webmailwindstreamnetmessagesecureapp1rqr.ga",nocase; classtype:trojan-activity; sid:100003398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webpresario.com",nocase; classtype:trojan-activity; sid:100003399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"website-work.com",nocase; classtype:trojan-activity; sid:100003400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weinsteincounseling.com",nocase; classtype:trojan-activity; sid:100003401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wfinance.com.br",nocase; classtype:trojan-activity; sid:100003402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whcms.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whiteresponse.com",nocase; classtype:trojan-activity; sid:100003404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wi522012.ferozo.com",nocase; classtype:trojan-activity; sid:100003405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikalen.co.za",nocase; classtype:trojan-activity; sid:100003406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildnights.co.uk",nocase; classtype:trojan-activity; sid:100003407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildtrust.mediadevstaging.com",nocase; classtype:trojan-activity; sid:100003408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"willow-nettica.com",nocase; classtype:trojan-activity; sid:100003409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wimbamusica.com",nocase; classtype:trojan-activity; sid:100003410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"windcomtechnologies.com",nocase; classtype:trojan-activity; sid:100003411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wishesconcierge.com",nocase; classtype:trojan-activity; sid:100003412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woezon.agency",nocase; classtype:trojan-activity; sid:100003413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wolfgang-brodte.de",nocase; classtype:trojan-activity; sid:100003414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wonderhawaii.com",nocase; classtype:trojan-activity; sid:100003415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woodsytech.com",nocase; classtype:trojan-activity; sid:100003416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wordpress.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100003417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"workingsolutionsrome.org",nocase; classtype:trojan-activity; sid:100003418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wozata.000webhostapp.com",nocase; classtype:trojan-activity; sid:100003419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wp.readhere.in",nocase; classtype:trojan-activity; sid:100003420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wpdemo.101clients.com.au",nocase; classtype:trojan-activity; sid:100003421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"writtendeer.com",nocase; classtype:trojan-activity; sid:100003422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ws5588.f3322.net",nocase; classtype:trojan-activity; sid:100003423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wsdyrmtcntlfarmtwsvb.dns.army",nocase; classtype:trojan-activity; sid:100003424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wyklej.pl",nocase; classtype:trojan-activity; sid:100003425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"x-iting.de",nocase; classtype:trojan-activity; sid:100003426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"x2vn.com",nocase; classtype:trojan-activity; sid:100003427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xia.beihaixue.com",nocase; classtype:trojan-activity; sid:100003428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xixaoclothing.com",nocase; classtype:trojan-activity; sid:100003429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xk.996is.com",nocase; classtype:trojan-activity; sid:100003430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--80akinnkiib6h.xn--90ais",nocase; classtype:trojan-activity; sid:100003431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--polimerbizmimarlk-rvc.com",nocase; classtype:trojan-activity; sid:100003432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ybom.urbanolab.com",nocase; classtype:trojan-activity; sid:100003433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yeichner.com",nocase; classtype:trojan-activity; sid:100003434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ylfpremium.com",nocase; classtype:trojan-activity; sid:100003435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yoast.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yourclub1.com",nocase; classtype:trojan-activity; sid:100003437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yourtopdog.com.au",nocase; classtype:trojan-activity; sid:100003438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"youtubetrainingacademy.com",nocase; classtype:trojan-activity; sid:100003439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yskadvisors.com",nocase; classtype:trojan-activity; sid:100003440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yummyyogaudaipur.com",nocase; classtype:trojan-activity; sid:100003441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yzkzixun.com",nocase; classtype:trojan-activity; sid:100003442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zmedcoach.com",nocase; classtype:trojan-activity; sid:100003443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zytrox.tk",nocase; classtype:trojan-activity; sid:100003444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zz.690tx.com",nocase; classtype:trojan-activity; sid:100003445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100003446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/86.exe",nocase; classtype:trojan-activity; sid:100003447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/c64.exe",nocase; classtype:trojan-activity; sid:100003448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amumufree.weebly.com",nocase; http_uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe",nocase; classtype:trojan-activity; sid:100003449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"analogx.com",nocase; http_uri; content:"/files/proxyi.exe",nocase; classtype:trojan-activity; sid:100003450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe",nocase; classtype:trojan-activity; sid:100003451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/dvdfv/anjj/downloads/jami.exe",nocase; classtype:trojan-activity; sid:100003452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/johnhast/efve/downloads/versiumr.exe",nocase; classtype:trojan-activity; sid:100003453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/johnhast/efve/downloads/versiumrr.exe",nocase; classtype:trojan-activity; sid:100003454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/4.exe",nocase; classtype:trojan-activity; sid:100003455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/6.exe",nocase; classtype:trojan-activity; sid:100003456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/labesoftware/update/downloads/boost-fps.exe",nocase; classtype:trojan-activity; sid:100003457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/labesoftware/update/downloads/install_plugin_x64_x86.exe",nocase; classtype:trojan-activity; sid:100003458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/labesoftware/update/downloads/vpn_free.exe",nocase; classtype:trojan-activity; sid:100003459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/clr.exe",nocase; classtype:trojan-activity; sid:100003460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatev.exe",nocase; classtype:trojan-activity; sid:100003461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/work.exe",nocase; classtype:trojan-activity; sid:100003462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/component.exe",nocase; classtype:trojan-activity; sid:100003463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe",nocase; classtype:trojan-activity; sid:100003464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/regsvc.exe",nocase; classtype:trojan-activity; sid:100003465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/skygaming/updates/downloads/update.exe",nocase; classtype:trojan-activity; sid:100003466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/001.txt",nocase; classtype:trojan-activity; sid:100003467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1488.txt",nocase; classtype:trojan-activity; sid:100003468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1_cr.txt",nocase; classtype:trojan-activity; sid:100003469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1cr.txt",nocase; classtype:trojan-activity; sid:100003470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1fc2d.txt",nocase; classtype:trojan-activity; sid:100003471; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/26a5.txt",nocase; classtype:trojan-activity; sid:100003472; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt",nocase; classtype:trojan-activity; sid:100003473; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/abjects.txt",nocase; classtype:trojan-activity; sid:100003474; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/attached.txt",nocase; classtype:trojan-activity; sid:100003475; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/b7f2c.exe",nocase; classtype:trojan-activity; sid:100003476; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/battletext.txt",nocase; classtype:trojan-activity; sid:100003477; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe",nocase; classtype:trojan-activity; sid:100003478; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe",nocase; classtype:trojan-activity; sid:100003479; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build.txt",nocase; classtype:trojan-activity; sid:100003480; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_makros.exe",nocase; classtype:trojan-activity; sid:100003481; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_silent.txt",nocase; classtype:trojan-activity; sid:100003482; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_sup.txt",nocase; classtype:trojan-activity; sid:100003483; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe",nocase; classtype:trojan-activity; sid:100003484; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt",nocase; classtype:trojan-activity; sid:100003485; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcr.txt",nocase; classtype:trojan-activity; sid:100003486; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildss.txt",nocase; classtype:trojan-activity; sid:100003487; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientnik.txt",nocase; classtype:trojan-activity; sid:100003488; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientrevers.txt",nocase; classtype:trojan-activity; sid:100003489; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dcrat.exe",nocase; classtype:trojan-activity; sid:100003490; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices.exe",nocase; classtype:trojan-activity; sid:100003491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe",nocase; classtype:trojan-activity; sid:100003492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hans.txt",nocase; classtype:trojan-activity; sid:100003493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hulu.txt",nocase; classtype:trojan-activity; sid:100003494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfive.txt",nocase; classtype:trojan-activity; sid:100003495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfour.txt",nocase; classtype:trojan-activity; sid:100003496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelone.txt",nocase; classtype:trojan-activity; sid:100003497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelthree.txt",nocase; classtype:trojan-activity; sid:100003498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/inteltwo.txt",nocase; classtype:trojan-activity; sid:100003499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe",nocase; classtype:trojan-activity; sid:100003500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/kleiman.exe",nocase; classtype:trojan-activity; sid:100003501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe",nocase; classtype:trojan-activity; sid:100003502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/notepadplus.txt",nocase; classtype:trojan-activity; sid:100003503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe",nocase; classtype:trojan-activity; sid:100003504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.exe",nocase; classtype:trojan-activity; sid:100003505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.txt",nocase; classtype:trojan-activity; sid:100003506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt",nocase; classtype:trojan-activity; sid:100003507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/putty.txt",nocase; classtype:trojan-activity; sid:100003508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/rockethcd.txt",nocase; classtype:trojan-activity; sid:100003509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/scvhost900.exe",nocase; classtype:trojan-activity; sid:100003510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/sessionwin.exe",nocase; classtype:trojan-activity; sid:100003511; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/siliculose.txt",nocase; classtype:trojan-activity; sid:100003512; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/statemobi.txt",nocase; classtype:trojan-activity; sid:100003513; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers.exe",nocase; classtype:trojan-activity; sid:100003514; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers2.exe",nocase; classtype:trojan-activity; sid:100003515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stgedo.exe",nocase; classtype:trojan-activity; sid:100003516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/svcperf.txt",nocase; classtype:trojan-activity; sid:100003517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe",nocase; classtype:trojan-activity; sid:100003518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurjok.txt",nocase; classtype:trojan-activity; sid:100003519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurusbabac.exe",nocase; classtype:trojan-activity; sid:100003520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/telekiller.exe",nocase; classtype:trojan-activity; sid:100003521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateandr.txt",nocase; classtype:trojan-activity; sid:100003522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/vhajeja.txt",nocase; classtype:trojan-activity; sid:100003523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/word.txt",nocase; classtype:trojan-activity; sid:100003524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/www.txt",nocase; classtype:trojan-activity; sid:100003525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/xlsd.txt",nocase; classtype:trojan-activity; sid:100003526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin",nocase; classtype:trojan-activity; sid:100003527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin",nocase; classtype:trojan-activity; sid:100003528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cd.textfiles.com",nocase; http_uri; content:"/hmatrix/data/hack1226.exe",nocase; classtype:trojan-activity; sid:100003529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq",nocase; classtype:trojan-activity; sid:100003530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/816070119281131570/816070273254162442/all.txt",nocase; classtype:trojan-activity; sid:100003531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/825372018244583454/826848185246023750/loaddd.exe",nocase; classtype:trojan-activity; sid:100003532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/825372018244583454/826848348342059008/zeppelin.exe",nocase; classtype:trojan-activity; sid:100003533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/825372018244583454/826848405258633277/build.exe",nocase; classtype:trojan-activity; sid:100003534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/826198252025675816/826537386485612574/china.png",nocase; classtype:trojan-activity; sid:100003535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin",nocase; classtype:trojan-activity; sid:100003536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe",nocase; classtype:trojan-activity; sid:100003537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chiptune.com",nocase; http_uri; content:"/razor/rzr-winner_intro.zip",nocase; classtype:trojan-activity; sid:100003538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz",nocase; classtype:trojan-activity; sid:100003539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar",nocase; classtype:trojan-activity; sid:100003540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codeload.github.com",nocase; http_uri; content:"/meteoradminz/hidden-tear/zip/master",nocase; classtype:trojan-activity; sid:100003541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colfincas.com",nocase; http_uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/",nocase; classtype:trojan-activity; sid:100003542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deepfreedom.org",nocase; http_uri; content:"/qz0h69.pdf",nocase; classtype:trojan-activity; sid:100003543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?export=download&id=1ktcghnmcwws43wzscphukbfnwtuaxidx&revid=0b8z0b7_i5sirk2xrtehmstg0vxvit3b4n3lmbdrdrjrodndrpq",nocase; classtype:trojan-activity; sid:100003544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com.it-barcelona.com",nocase; http_uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe",nocase; classtype:trojan-activity; sid:100003545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm",nocase; classtype:trojan-activity; sid:100003546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=12khl-unz2np4q54b2jgpwlsh6cuz0pss",nocase; classtype:trojan-activity; sid:100003547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=13sfskplrox3d7uantwjj_trs6ciwvqa1",nocase; classtype:trojan-activity; sid:100003548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch",nocase; classtype:trojan-activity; sid:100003549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=152yoztzpbx_bbpxepfackfklg8c1eao6",nocase; classtype:trojan-activity; sid:100003550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=15hcgek7odccdafzf-9gvibnlgkirj4uo",nocase; classtype:trojan-activity; sid:100003551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox",nocase; classtype:trojan-activity; sid:100003552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=194lqzukzvt-jtdxmihcvhd0yk1sxoybk",nocase; classtype:trojan-activity; sid:100003553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig",nocase; classtype:trojan-activity; sid:100003554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn",nocase; classtype:trojan-activity; sid:100003555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1br5iufkkmmfeipqo3ecviqykbcdgcnio",nocase; classtype:trojan-activity; sid:100003556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv",nocase; classtype:trojan-activity; sid:100003557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1cos43rmscrescxk3u40qjuqbwr-pydsn",nocase; classtype:trojan-activity; sid:100003558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben",nocase; classtype:trojan-activity; sid:100003559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1dnm3wtjf6ud5fv6zop9cvbr4rs2of1-n",nocase; classtype:trojan-activity; sid:100003560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1dqin1sdd6rbah3sggzsxzeqgrkmhjnqm",nocase; classtype:trojan-activity; sid:100003561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi",nocase; classtype:trojan-activity; sid:100003562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1fensc6gc0fww0gbevsrnwwnlajypzdvv",nocase; classtype:trojan-activity; sid:100003563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1htinwtfrw1wc3_ma8odztnq0qpnic2q6",nocase; classtype:trojan-activity; sid:100003564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei",nocase; classtype:trojan-activity; sid:100003565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je",nocase; classtype:trojan-activity; sid:100003566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr",nocase; classtype:trojan-activity; sid:100003567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1jkov2g5s1xkcq4bfb3uvmd6inhadatrg",nocase; classtype:trojan-activity; sid:100003568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1jnarxelz8gtbkg5pa_s0rc8kv3ejkepn",nocase; classtype:trojan-activity; sid:100003569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1kjcylye1dbmhystyyotz-3pagktkhlhq",nocase; classtype:trojan-activity; sid:100003570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1lsv4sko083sywwjndgqnsh_6sgqodqtu",nocase; classtype:trojan-activity; sid:100003571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1mwgdd3lxuuk-bnsrm1rpclom0cmx7wob",nocase; classtype:trojan-activity; sid:100003572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y",nocase; classtype:trojan-activity; sid:100003573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd",nocase; classtype:trojan-activity; sid:100003574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1nmf6kty3xsoygjxjhb-bsafvlfy-0lt2",nocase; classtype:trojan-activity; sid:100003575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw",nocase; classtype:trojan-activity; sid:100003576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1p5fvqkxzwoiu_uauzbmrxpklsetculad",nocase; classtype:trojan-activity; sid:100003577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej",nocase; classtype:trojan-activity; sid:100003578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1q1dwckludrpqijtrpw14_60d5nu7n97t",nocase; classtype:trojan-activity; sid:100003579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1r9f9irwhutxozsbp2h9erd_a7fa2pwko",nocase; classtype:trojan-activity; sid:100003580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1s221a6wpx6i7nfrztnhh9priojtybuxq",nocase; classtype:trojan-activity; sid:100003581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1sjvkrinuscxqmbkdeusxaezazbiagnv3",nocase; classtype:trojan-activity; sid:100003582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1so1trfuzt5-giahetghfhmd-_ot3rq35",nocase; classtype:trojan-activity; sid:100003583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn",nocase; classtype:trojan-activity; sid:100003584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw",nocase; classtype:trojan-activity; sid:100003585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1uowridpynurgqlgqjbtgramigo2a9v76",nocase; classtype:trojan-activity; sid:100003586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55",nocase; classtype:trojan-activity; sid:100003587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t",nocase; classtype:trojan-activity; sid:100003588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vjq92eqivh01yxmal20whl2es3ld6nxb",nocase; classtype:trojan-activity; sid:100003589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e",nocase; classtype:trojan-activity; sid:100003590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi",nocase; classtype:trojan-activity; sid:100003591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58",nocase; classtype:trojan-activity; sid:100003592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi",nocase; classtype:trojan-activity; sid:100003593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv",nocase; classtype:trojan-activity; sid:100003594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yqpuxjbnjokc5fjgt-8xzuybr97rtvg2",nocase; classtype:trojan-activity; sid:100003595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ywkgalidldb32pio6ywmbyvdk7oar3yy",nocase; classtype:trojan-activity; sid:100003596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr",nocase; classtype:trojan-activity; sid:100003597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0",nocase; classtype:trojan-activity; sid:100003598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/1zilg/",nocase; classtype:trojan-activity; sid:100003599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/qcgfmfvh/",nocase; classtype:trojan-activity; sid:100003600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-mudhra.com",nocase; http_uri; content:"/downloads/emclick.zip",nocase; classtype:trojan-activity; sid:100003601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/",nocase; classtype:trojan-activity; sid:100003602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/",nocase; classtype:trojan-activity; sid:100003603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/x/",nocase; classtype:trojan-activity; sid:100003604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/",nocase; classtype:trojan-activity; sid:100003605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//",nocase; classtype:trojan-activity; sid:100003606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///",nocase; classtype:trojan-activity; sid:100003607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////",nocase; classtype:trojan-activity; sid:100003608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"file.elecfans.com",nocase; http_uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe",nocase; classtype:trojan-activity; sid:100003609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls",nocase; classtype:trojan-activity; sid:100003610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx",nocase; classtype:trojan-activity; sid:100003611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gist.githubusercontent.com",nocase; http_uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe",nocase; classtype:trojan-activity; sid:100003612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostingcloud.racing",nocase; http_uri; content:"/7991.js",nocase; classtype:trojan-activity; sid:100003613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hqdecig.com",nocase; http_uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/",nocase; classtype:trojan-activity; sid:100003614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsecaravans.co.uk",nocase; http_uri; content:"/wp-admin/suy/",nocase; classtype:trojan-activity; sid:100003615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ia801802.us.archive.org",nocase; http_uri; content:"/19/items/startup_20210219/startup.txt",nocase; classtype:trojan-activity; sid:100003616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ie-best.net",nocase; http_uri; content:"/online-timer-kvhxz/ilxl/",nocase; classtype:trojan-activity; sid:100003617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100003618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/c64.exe",nocase; classtype:trojan-activity; sid:100003619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jcedu.org",nocase; http_uri; content:"/ebook/cs17.exe",nocase; classtype:trojan-activity; sid:100003620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1",nocase; classtype:trojan-activity; sid:100003621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2",nocase; classtype:trojan-activity; sid:100003622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3",nocase; classtype:trojan-activity; sid:100003623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karmakoincodes.weebly.com",nocase; http_uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe",nocase; classtype:trojan-activity; sid:100003624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kotakwarna.co.id",nocase; http_uri; content:"/dg/etrac/nf4emwz/",nocase; classtype:trojan-activity; sid:100003625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ksh.hu",nocase; http_uri; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe",nocase; classtype:trojan-activity; sid:100003626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kuaizip.com",nocase; http_uri; content:"/down/affiliate/kuaizip_setup_10029.exe",nocase; classtype:trojan-activity; sid:100003627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linuxforensicsbook.com.s3.amazonaws.com",nocase; http_uri; content:"/linuxforensicscode.zip",nocase; classtype:trojan-activity; sid:100003628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marcostrombetta.com.br",nocase; http_uri; content:"/ds/1802.gif",nocase; classtype:trojan-activity; sid:100003629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minpic.de",nocase; http_uri; content:"/k/big5/1giof6/",nocase; classtype:trojan-activity; sid:100003630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"morrobaydrugandgift.com",nocase; http_uri; content:"/wp-contentbak/t9m/",nocase; classtype:trojan-activity; sid:100003631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moumitas.com",nocase; http_uri; content:"/ds/0204.gif",nocase; classtype:trojan-activity; sid:100003632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"my.cloudme.com",nocase; http_uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe",nocase; classtype:trojan-activity; sid:100003633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/aacenc.exe",nocase; classtype:trojan-activity; sid:100003634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/doxillionsetup.exe",nocase; classtype:trojan-activity; sid:100003635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newyarlfm.weebly.com",nocase; http_uri; content:"/uploads/4/1/6/6/4166984/keygen.exe",nocase; classtype:trojan-activity; sid:100003636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhipcauytevietnhat.com",nocase; http_uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/",nocase; classtype:trojan-activity; sid:100003637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"note.youdao.com",nocase; http_uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a",nocase; classtype:trojan-activity; sid:100003638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oldschoolvalue.s3.amazonaws.com",nocase; http_uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe",nocase; classtype:trojan-activity; sid:100003639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq",nocase; classtype:trojan-activity; sid:100003640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq",nocase; classtype:trojan-activity; sid:100003641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21108&authkey=acq44gahejhwrag",nocase; classtype:trojan-activity; sid:100003642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa",nocase; classtype:trojan-activity; sid:100003643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq",nocase; classtype:trojan-activity; sid:100003644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe",nocase; classtype:trojan-activity; sid:100003645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg",nocase; classtype:trojan-activity; sid:100003646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0",nocase; classtype:trojan-activity; sid:100003647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g",nocase; classtype:trojan-activity; sid:100003648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140",nocase; classtype:trojan-activity; sid:100003649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130",nocase; classtype:trojan-activity; sid:100003650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135",nocase; classtype:trojan-activity; sid:100003651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732",nocase; classtype:trojan-activity; sid:100003652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4",nocase; classtype:trojan-activity; sid:100003653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100003654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100003655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0",nocase; classtype:trojan-activity; sid:100003656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100003657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100003658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100003659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100003660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq",nocase; classtype:trojan-activity; sid:100003661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko",nocase; classtype:trojan-activity; sid:100003662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw",nocase; classtype:trojan-activity; sid:100003663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma",nocase; classtype:trojan-activity; sid:100003664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48",nocase; classtype:trojan-activity; sid:100003665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq",nocase; classtype:trojan-activity; sid:100003666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg",nocase; classtype:trojan-activity; sid:100003667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw",nocase; classtype:trojan-activity; sid:100003668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq",nocase; classtype:trojan-activity; sid:100003669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d!184&authkey=ackbiiarirejcam",nocase; classtype:trojan-activity; sid:100003670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d%21184&authkey=ackbiiarirejcam",nocase; classtype:trojan-activity; sid:100003671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100003672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100003673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100003674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100003675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0!1667&authkey=an8otd7jzc7xgho",nocase; classtype:trojan-activity; sid:100003676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0%211667&authkey=an8otd7jzc7xgho",nocase; classtype:trojan-activity; sid:100003677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0da4ace18aa7d1e2&resid=da4ace18aa7d1e2%21131&authkey=adjn1y5pp4a10_c",nocase; classtype:trojan-activity; sid:100003678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100003679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100003680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw",nocase; classtype:trojan-activity; sid:100003681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0",nocase; classtype:trojan-activity; sid:100003682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a",nocase; classtype:trojan-activity; sid:100003683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4",nocase; classtype:trojan-activity; sid:100003684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo",nocase; classtype:trojan-activity; sid:100003685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100003686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100003687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f!286&authkey=almwisomhv3c0zc",nocase; classtype:trojan-activity; sid:100003688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc",nocase; classtype:trojan-activity; sid:100003689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100003690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100003691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100003692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100003693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100003694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100003695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve",nocase; classtype:trojan-activity; sid:100003696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w",nocase; classtype:trojan-activity; sid:100003697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100003698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100003699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg",nocase; classtype:trojan-activity; sid:100003700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60",nocase; classtype:trojan-activity; sid:100003701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg",nocase; classtype:trojan-activity; sid:100003702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4",nocase; classtype:trojan-activity; sid:100003703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c",nocase; classtype:trojan-activity; sid:100003704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0",nocase; classtype:trojan-activity; sid:100003705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc",nocase; classtype:trojan-activity; sid:100003706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c",nocase; classtype:trojan-activity; sid:100003707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!140&authkey=apn44x6bxlzq3ac",nocase; classtype:trojan-activity; sid:100003708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!151&authkey=aeuk7knodrpenek",nocase; classtype:trojan-activity; sid:100003709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!153&authkey=ao6e8g0bzbp_idw",nocase; classtype:trojan-activity; sid:100003710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!154&authkey=ah4chedbotzpmtq",nocase; classtype:trojan-activity; sid:100003711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!156&authkey=ajnqscnmrdonpkg",nocase; classtype:trojan-activity; sid:100003712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs",nocase; classtype:trojan-activity; sid:100003713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0",nocase; classtype:trojan-activity; sid:100003714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd",nocase; classtype:trojan-activity; sid:100003715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c",nocase; classtype:trojan-activity; sid:100003716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21140&authkey=apn44x6bxlzq3ac",nocase; classtype:trojan-activity; sid:100003717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21151&authkey=aeuk7knodrpenek",nocase; classtype:trojan-activity; sid:100003718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21153&authkey=ao6e8g0bzbp_idw",nocase; classtype:trojan-activity; sid:100003719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21154&authkey=ah4chedbotzpmtq",nocase; classtype:trojan-activity; sid:100003720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21156&authkey=ajnqscnmrdonpkg",nocase; classtype:trojan-activity; sid:100003721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe",nocase; classtype:trojan-activity; sid:100003722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk",nocase; classtype:trojan-activity; sid:100003723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100003724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu",nocase; classtype:trojan-activity; sid:100003725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k",nocase; classtype:trojan-activity; sid:100003726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo",nocase; classtype:trojan-activity; sid:100003727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga",nocase; classtype:trojan-activity; sid:100003728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2968c371f5450503&resid=2968c371f5450503!122&authkey=aaqhhxbnwfwrz28",nocase; classtype:trojan-activity; sid:100003729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0",nocase; classtype:trojan-activity; sid:100003730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620",nocase; classtype:trojan-activity; sid:100003731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo",nocase; classtype:trojan-activity; sid:100003732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e",nocase; classtype:trojan-activity; sid:100003733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100003734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100003735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw",nocase; classtype:trojan-activity; sid:100003736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw",nocase; classtype:trojan-activity; sid:100003737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4",nocase; classtype:trojan-activity; sid:100003738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w",nocase; classtype:trojan-activity; sid:100003739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100003740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8",nocase; classtype:trojan-activity; sid:100003741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100003742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw",nocase; classtype:trojan-activity; sid:100003743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100003744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100003745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100003746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100003747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq",nocase; classtype:trojan-activity; sid:100003748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o",nocase; classtype:trojan-activity; sid:100003749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1!223&authkey=aajr842bzum0yg8",nocase; classtype:trojan-activity; sid:100003750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8",nocase; classtype:trojan-activity; sid:100003751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc",nocase; classtype:trojan-activity; sid:100003752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0",nocase; classtype:trojan-activity; sid:100003753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus",nocase; classtype:trojan-activity; sid:100003754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100003755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100003756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100003757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100003758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100003759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100003760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100003761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100003762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk",nocase; classtype:trojan-activity; sid:100003763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4",nocase; classtype:trojan-activity; sid:100003764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4",nocase; classtype:trojan-activity; sid:100003765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge",nocase; classtype:trojan-activity; sid:100003766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs",nocase; classtype:trojan-activity; sid:100003767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3ee68228c34c236d&resid=3ee68228c34c236d%21129&authkey=apll6hu3-xetzxu",nocase; classtype:trojan-activity; sid:100003768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100003769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100003770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100003771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba!2203&authkey=ajvalmr5l8epwvm",nocase; classtype:trojan-activity; sid:100003772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba%212203&authkey=ajvalmr5l8epwvm",nocase; classtype:trojan-activity; sid:100003773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100003774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100003775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik",nocase; classtype:trojan-activity; sid:100003776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq",nocase; classtype:trojan-activity; sid:100003777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy",nocase; classtype:trojan-activity; sid:100003778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21141&authkey=aazwaw2xjms24o0",nocase; classtype:trojan-activity; sid:100003779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100003780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100003781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y",nocase; classtype:trojan-activity; sid:100003782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100003783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100003784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100003785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100003786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y",nocase; classtype:trojan-activity; sid:100003787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo",nocase; classtype:trojan-activity; sid:100003788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4",nocase; classtype:trojan-activity; sid:100003789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm",nocase; classtype:trojan-activity; sid:100003790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu",nocase; classtype:trojan-activity; sid:100003791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100003792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100003793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc",nocase; classtype:trojan-activity; sid:100003794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y",nocase; classtype:trojan-activity; sid:100003795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8",nocase; classtype:trojan-activity; sid:100003796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc",nocase; classtype:trojan-activity; sid:100003797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs",nocase; classtype:trojan-activity; sid:100003798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts",nocase; classtype:trojan-activity; sid:100003799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc",nocase; classtype:trojan-activity; sid:100003800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg",nocase; classtype:trojan-activity; sid:100003801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y",nocase; classtype:trojan-activity; sid:100003802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday",nocase; classtype:trojan-activity; sid:100003803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0",nocase; classtype:trojan-activity; sid:100003804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas",nocase; classtype:trojan-activity; sid:100003805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve",nocase; classtype:trojan-activity; sid:100003806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy",nocase; classtype:trojan-activity; sid:100003807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14",nocase; classtype:trojan-activity; sid:100003808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i",nocase; classtype:trojan-activity; sid:100003809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa",nocase; classtype:trojan-activity; sid:100003810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu",nocase; classtype:trojan-activity; sid:100003811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c",nocase; classtype:trojan-activity; sid:100003812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy",nocase; classtype:trojan-activity; sid:100003813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q",nocase; classtype:trojan-activity; sid:100003814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm",nocase; classtype:trojan-activity; sid:100003815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4",nocase; classtype:trojan-activity; sid:100003816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho",nocase; classtype:trojan-activity; sid:100003817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18",nocase; classtype:trojan-activity; sid:100003818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q",nocase; classtype:trojan-activity; sid:100003819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm",nocase; classtype:trojan-activity; sid:100003820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na",nocase; classtype:trojan-activity; sid:100003821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk",nocase; classtype:trojan-activity; sid:100003822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe",nocase; classtype:trojan-activity; sid:100003823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi",nocase; classtype:trojan-activity; sid:100003824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc",nocase; classtype:trojan-activity; sid:100003825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc",nocase; classtype:trojan-activity; sid:100003826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100003827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100003828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100003829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100003830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100003831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100003832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100003833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100003834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100003835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100003836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100003837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100003838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4",nocase; classtype:trojan-activity; sid:100003839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu",nocase; classtype:trojan-activity; sid:100003840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi",nocase; classtype:trojan-activity; sid:100003841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8",nocase; classtype:trojan-activity; sid:100003842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8",nocase; classtype:trojan-activity; sid:100003843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100003844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100003845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8",nocase; classtype:trojan-activity; sid:100003846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100003847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100003848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100003849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100003850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g",nocase; classtype:trojan-activity; sid:100003851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum",nocase; classtype:trojan-activity; sid:100003852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi",nocase; classtype:trojan-activity; sid:100003853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy",nocase; classtype:trojan-activity; sid:100003854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o",nocase; classtype:trojan-activity; sid:100003855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa",nocase; classtype:trojan-activity; sid:100003856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100003857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100003858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc",nocase; classtype:trojan-activity; sid:100003859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk",nocase; classtype:trojan-activity; sid:100003860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea",nocase; classtype:trojan-activity; sid:100003861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100003862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100003863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100003864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100003865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100003866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo",nocase; classtype:trojan-activity; sid:100003867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva",nocase; classtype:trojan-activity; sid:100003868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc",nocase; classtype:trojan-activity; sid:100003869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles",nocase; classtype:trojan-activity; sid:100003870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg",nocase; classtype:trojan-activity; sid:100003871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100003872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100003873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100003874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100003875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw",nocase; classtype:trojan-activity; sid:100003876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8",nocase; classtype:trojan-activity; sid:100003877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq",nocase; classtype:trojan-activity; sid:100003878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug",nocase; classtype:trojan-activity; sid:100003879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua",nocase; classtype:trojan-activity; sid:100003880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe",nocase; classtype:trojan-activity; sid:100003881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i",nocase; classtype:trojan-activity; sid:100003882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa",nocase; classtype:trojan-activity; sid:100003883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe",nocase; classtype:trojan-activity; sid:100003884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m",nocase; classtype:trojan-activity; sid:100003885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi",nocase; classtype:trojan-activity; sid:100003886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21198&authkey=akq4jrbjm6spd9m",nocase; classtype:trojan-activity; sid:100003887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!109&authkey=ap-okubj9bvtlc0",nocase; classtype:trojan-activity; sid:100003888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21106&authkey=an9dhtmtufpis-m",nocase; classtype:trojan-activity; sid:100003889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21109&authkey=ap-okubj9bvtlc0",nocase; classtype:trojan-activity; sid:100003890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi",nocase; classtype:trojan-activity; sid:100003891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e",nocase; classtype:trojan-activity; sid:100003892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c",nocase; classtype:trojan-activity; sid:100003893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100003894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c",nocase; classtype:trojan-activity; sid:100003895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4",nocase; classtype:trojan-activity; sid:100003896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo",nocase; classtype:trojan-activity; sid:100003897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2!517&authkey=akfewcyiwlwomyk",nocase; classtype:trojan-activity; sid:100003898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji",nocase; classtype:trojan-activity; sid:100003899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21517&authkey=akfewcyiwlwomyk",nocase; classtype:trojan-activity; sid:100003900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100003901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100003902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg",nocase; classtype:trojan-activity; sid:100003903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70",nocase; classtype:trojan-activity; sid:100003904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc",nocase; classtype:trojan-activity; sid:100003905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100003906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100003907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100003908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100003909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw",nocase; classtype:trojan-activity; sid:100003910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq",nocase; classtype:trojan-activity; sid:100003911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm",nocase; classtype:trojan-activity; sid:100003912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100003913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100003914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8",nocase; classtype:trojan-activity; sid:100003915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100003916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100003917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!301&authkey=abquzhtdjg5pryk",nocase; classtype:trojan-activity; sid:100003918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!302&authkey=al2_xstzqulnnqw",nocase; classtype:trojan-activity; sid:100003919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!305&authkey=an-uuhplpk2zp5u",nocase; classtype:trojan-activity; sid:100003920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21301&authkey=abquzhtdjg5pryk",nocase; classtype:trojan-activity; sid:100003921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21302&authkey=al2_xstzqulnnqw",nocase; classtype:trojan-activity; sid:100003922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21305&authkey=an-uuhplpk2zp5u",nocase; classtype:trojan-activity; sid:100003923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu",nocase; classtype:trojan-activity; sid:100003924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i",nocase; classtype:trojan-activity; sid:100003925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam",nocase; classtype:trojan-activity; sid:100003926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble",nocase; classtype:trojan-activity; sid:100003927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60",nocase; classtype:trojan-activity; sid:100003928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k",nocase; classtype:trojan-activity; sid:100003929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8",nocase; classtype:trojan-activity; sid:100003930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg",nocase; classtype:trojan-activity; sid:100003931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte",nocase; classtype:trojan-activity; sid:100003932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!106&authkey=ahu5s4ttjvxbnxo",nocase; classtype:trojan-activity; sid:100003933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!107&authkey=abj3eccentbeaqa",nocase; classtype:trojan-activity; sid:100003934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!108&authkey=amvcygo4prlgt4i",nocase; classtype:trojan-activity; sid:100003935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!110&authkey=ahzuehvk5nvzo90",nocase; classtype:trojan-activity; sid:100003936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21106&authkey=ahu5s4ttjvxbnxo",nocase; classtype:trojan-activity; sid:100003937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21107&authkey=abj3eccentbeaqa",nocase; classtype:trojan-activity; sid:100003938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21108&authkey=amvcygo4prlgt4i",nocase; classtype:trojan-activity; sid:100003939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21110&authkey=ahzuehvk5nvzo90",nocase; classtype:trojan-activity; sid:100003940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34",nocase; classtype:trojan-activity; sid:100003941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w",nocase; classtype:trojan-activity; sid:100003942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta",nocase; classtype:trojan-activity; sid:100003943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100003944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100003945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100003946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100003947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm",nocase; classtype:trojan-activity; sid:100003948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125570&authkey=aejqgjglwurnb0a",nocase; classtype:trojan-activity; sid:100003949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq",nocase; classtype:trojan-activity; sid:100003950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k",nocase; classtype:trojan-activity; sid:100003951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100003952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100003953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100003954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100003955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100003956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100003957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs",nocase; classtype:trojan-activity; sid:100003958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm",nocase; classtype:trojan-activity; sid:100003959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8",nocase; classtype:trojan-activity; sid:100003960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm",nocase; classtype:trojan-activity; sid:100003961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21444&authkey=abzxvycu0ggtmg8",nocase; classtype:trojan-activity; sid:100003962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c",nocase; classtype:trojan-activity; sid:100003963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0",nocase; classtype:trojan-activity; sid:100003964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq",nocase; classtype:trojan-activity; sid:100003965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda",nocase; classtype:trojan-activity; sid:100003966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm",nocase; classtype:trojan-activity; sid:100003967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk",nocase; classtype:trojan-activity; sid:100003968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4",nocase; classtype:trojan-activity; sid:100003969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c",nocase; classtype:trojan-activity; sid:100003970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100003971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100003972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4",nocase; classtype:trojan-activity; sid:100003973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=89360b4c7415c088&resid=89360b4c7415c088%21106&authkey=akfcfq3zq5oof2i",nocase; classtype:trojan-activity; sid:100003974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=89360b4c7415c088&resid=89360b4c7415c088%21108&authkey=amfbkmapqbvzpvk",nocase; classtype:trojan-activity; sid:100003975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk",nocase; classtype:trojan-activity; sid:100003976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk",nocase; classtype:trojan-activity; sid:100003977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae",nocase; classtype:trojan-activity; sid:100003978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0",nocase; classtype:trojan-activity; sid:100003979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8",nocase; classtype:trojan-activity; sid:100003980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!254&authkey=ajt5wxegbvzbwqa",nocase; classtype:trojan-activity; sid:100003981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!255&authkey=aaimhpp89qmcfhc",nocase; classtype:trojan-activity; sid:100003982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33%21254&authkey=ajt5wxegbvzbwqa",nocase; classtype:trojan-activity; sid:100003983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my",nocase; classtype:trojan-activity; sid:100003984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc",nocase; classtype:trojan-activity; sid:100003985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby",nocase; classtype:trojan-activity; sid:100003986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo",nocase; classtype:trojan-activity; sid:100003987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti",nocase; classtype:trojan-activity; sid:100003988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!112&authkey=af43qpcgl0t2f5o",nocase; classtype:trojan-activity; sid:100003989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8",nocase; classtype:trojan-activity; sid:100003990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o",nocase; classtype:trojan-activity; sid:100003991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8",nocase; classtype:trojan-activity; sid:100003992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m",nocase; classtype:trojan-activity; sid:100003993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w",nocase; classtype:trojan-activity; sid:100003994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100003995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100003996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k",nocase; classtype:trojan-activity; sid:100003997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm",nocase; classtype:trojan-activity; sid:100003998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue",nocase; classtype:trojan-activity; sid:100003999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma",nocase; classtype:trojan-activity; sid:100004000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg",nocase; classtype:trojan-activity; sid:100004001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq",nocase; classtype:trojan-activity; sid:100004002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs",nocase; classtype:trojan-activity; sid:100004003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho",nocase; classtype:trojan-activity; sid:100004004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc",nocase; classtype:trojan-activity; sid:100004005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w",nocase; classtype:trojan-activity; sid:100004006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm",nocase; classtype:trojan-activity; sid:100004007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0",nocase; classtype:trojan-activity; sid:100004008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy",nocase; classtype:trojan-activity; sid:100004009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm",nocase; classtype:trojan-activity; sid:100004010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi",nocase; classtype:trojan-activity; sid:100004011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi",nocase; classtype:trojan-activity; sid:100004012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8",nocase; classtype:trojan-activity; sid:100004013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100004014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100004015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o",nocase; classtype:trojan-activity; sid:100004016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4",nocase; classtype:trojan-activity; sid:100004017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi",nocase; classtype:trojan-activity; sid:100004018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100004019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100004020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo",nocase; classtype:trojan-activity; sid:100004021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq",nocase; classtype:trojan-activity; sid:100004022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a31988151cf6813e&resid=a31988151cf6813e%21107&authkey=ab9lanzt1aj_0ws",nocase; classtype:trojan-activity; sid:100004023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi",nocase; classtype:trojan-activity; sid:100004024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs",nocase; classtype:trojan-activity; sid:100004025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw",nocase; classtype:trojan-activity; sid:100004026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o",nocase; classtype:trojan-activity; sid:100004027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs",nocase; classtype:trojan-activity; sid:100004028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw",nocase; classtype:trojan-activity; sid:100004029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu",nocase; classtype:trojan-activity; sid:100004030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21256&authkey=aapnly5qifymcvw",nocase; classtype:trojan-activity; sid:100004031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100004032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100004033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi",nocase; classtype:trojan-activity; sid:100004034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc",nocase; classtype:trojan-activity; sid:100004035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy",nocase; classtype:trojan-activity; sid:100004036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc",nocase; classtype:trojan-activity; sid:100004037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey",nocase; classtype:trojan-activity; sid:100004038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg",nocase; classtype:trojan-activity; sid:100004039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui",nocase; classtype:trojan-activity; sid:100004040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi",nocase; classtype:trojan-activity; sid:100004041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818!129&authkey=aesewk3cf5vbrxw",nocase; classtype:trojan-activity; sid:100004042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818%21129&authkey=aesewk3cf5vbrxw",nocase; classtype:trojan-activity; sid:100004043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk",nocase; classtype:trojan-activity; sid:100004044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw",nocase; classtype:trojan-activity; sid:100004045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100004046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100004047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e",nocase; classtype:trojan-activity; sid:100004048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100004049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100004050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u",nocase; classtype:trojan-activity; sid:100004051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm",nocase; classtype:trojan-activity; sid:100004052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy",nocase; classtype:trojan-activity; sid:100004053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc",nocase; classtype:trojan-activity; sid:100004054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy",nocase; classtype:trojan-activity; sid:100004055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84",nocase; classtype:trojan-activity; sid:100004056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo",nocase; classtype:trojan-activity; sid:100004057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw",nocase; classtype:trojan-activity; sid:100004058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww",nocase; classtype:trojan-activity; sid:100004059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy",nocase; classtype:trojan-activity; sid:100004060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w",nocase; classtype:trojan-activity; sid:100004061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq",nocase; classtype:trojan-activity; sid:100004062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100004063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100004064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg",nocase; classtype:trojan-activity; sid:100004065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg",nocase; classtype:trojan-activity; sid:100004066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100004067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100004068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m",nocase; classtype:trojan-activity; sid:100004069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8",nocase; classtype:trojan-activity; sid:100004070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1047&authkey=aod6jbxyicq2v4g",nocase; classtype:trojan-activity; sid:100004071; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211047&authkey=aod6jbxyicq2v4g",nocase; classtype:trojan-activity; sid:100004072; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100004073; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100004074; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq",nocase; classtype:trojan-activity; sid:100004075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm",nocase; classtype:trojan-activity; sid:100004076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai",nocase; classtype:trojan-activity; sid:100004077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk",nocase; classtype:trojan-activity; sid:100004078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100004079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100004080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100004081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100004082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100004083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100004084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100004085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100004086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100004087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100004088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100004089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100004090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100004091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100004092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100004093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100004094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100004095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100004096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100004097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100004098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8",nocase; classtype:trojan-activity; sid:100004099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc",nocase; classtype:trojan-activity; sid:100004100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc",nocase; classtype:trojan-activity; sid:100004101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs",nocase; classtype:trojan-activity; sid:100004102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m",nocase; classtype:trojan-activity; sid:100004103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga",nocase; classtype:trojan-activity; sid:100004104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg",nocase; classtype:trojan-activity; sid:100004105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100004106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100004107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw",nocase; classtype:trojan-activity; sid:100004108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cda6c13b54bbe48c&resid=cda6c13b54bbe48c!44331&authkey=afohia-wo-alwiy",nocase; classtype:trojan-activity; sid:100004109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cda6c13b54bbe48c&resid=cda6c13b54bbe48c%2144331&authkey=afohia-wo-alwiy",nocase; classtype:trojan-activity; sid:100004110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100004111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100004112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100004113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100004114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100004115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100004116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100004117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100004118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100004119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100004120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0",nocase; classtype:trojan-activity; sid:100004121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d4d413b6e7cf7088&resid=d4d413b6e7cf7088%211271&authkey=akz65bxpgvdxjb8",nocase; classtype:trojan-activity; sid:100004122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100004123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100004124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100004125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100004126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy",nocase; classtype:trojan-activity; sid:100004127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe",nocase; classtype:trojan-activity; sid:100004128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq",nocase; classtype:trojan-activity; sid:100004129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4",nocase; classtype:trojan-activity; sid:100004130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq",nocase; classtype:trojan-activity; sid:100004131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100004132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100004133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100004134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100004135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100004136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100004137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2!1818&authkey=anh2wga7qmhbmuo",nocase; classtype:trojan-activity; sid:100004138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2%211818&authkey=anh2wga7qmhbmuo",nocase; classtype:trojan-activity; sid:100004139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw",nocase; classtype:trojan-activity; sid:100004140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0",nocase; classtype:trojan-activity; sid:100004141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4",nocase; classtype:trojan-activity; sid:100004142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs",nocase; classtype:trojan-activity; sid:100004143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0",nocase; classtype:trojan-activity; sid:100004144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q",nocase; classtype:trojan-activity; sid:100004145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2!107&authkey=af-bicrg1c6vgck",nocase; classtype:trojan-activity; sid:100004146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2%21107&authkey=af-bicrg1c6vgck",nocase; classtype:trojan-activity; sid:100004147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co",nocase; classtype:trojan-activity; sid:100004148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co",nocase; classtype:trojan-activity; sid:100004149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc",nocase; classtype:trojan-activity; sid:100004150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc",nocase; classtype:trojan-activity; sid:100004151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0",nocase; classtype:trojan-activity; sid:100004152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c",nocase; classtype:trojan-activity; sid:100004153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg",nocase; classtype:trojan-activity; sid:100004154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100004155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100004156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq",nocase; classtype:trojan-activity; sid:100004157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e627fc797baa3032&resid=e627fc797baa3032!2324&authkey=aa8i-r7ixmcraha",nocase; classtype:trojan-activity; sid:100004158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e627fc797baa3032&resid=e627fc797baa3032%212324&authkey=aa8i-r7ixmcraha",nocase; classtype:trojan-activity; sid:100004159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke",nocase; classtype:trojan-activity; sid:100004160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom",nocase; classtype:trojan-activity; sid:100004161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da",nocase; classtype:trojan-activity; sid:100004162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100004163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100004164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8!148&authkey=agjcwq650c8wdbm",nocase; classtype:trojan-activity; sid:100004165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8!150&authkey=ami5aqoinvosjle",nocase; classtype:trojan-activity; sid:100004166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8%21148&authkey=agjcwq650c8wdbm",nocase; classtype:trojan-activity; sid:100004167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8%21150&authkey=ami5aqoinvosjle",nocase; classtype:trojan-activity; sid:100004168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0",nocase; classtype:trojan-activity; sid:100004169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100004170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100004171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai",nocase; classtype:trojan-activity; sid:100004172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8",nocase; classtype:trojan-activity; sid:100004173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns",nocase; classtype:trojan-activity; sid:100004174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8",nocase; classtype:trojan-activity; sid:100004175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ef7cc06ce7ffafb8&resid=ef7cc06ce7ffafb8%21108&authkey=anmpeqm9gm_zv9m",nocase; classtype:trojan-activity; sid:100004176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100004177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100004178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100004179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100004180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100004181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0",nocase; classtype:trojan-activity; sid:100004182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw",nocase; classtype:trojan-activity; sid:100004183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e",nocase; classtype:trojan-activity; sid:100004184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu",nocase; classtype:trojan-activity; sid:100004185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq",nocase; classtype:trojan-activity; sid:100004186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k",nocase; classtype:trojan-activity; sid:100004187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie",nocase; classtype:trojan-activity; sid:100004188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c",nocase; classtype:trojan-activity; sid:100004189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta",nocase; classtype:trojan-activity; sid:100004190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o",nocase; classtype:trojan-activity; sid:100004191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao",nocase; classtype:trojan-activity; sid:100004192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!226&authkey=adho6klfkjflaqk",nocase; classtype:trojan-activity; sid:100004193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!229&authkey=akvo12quxgcwnk8",nocase; classtype:trojan-activity; sid:100004194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!234&authkey=abhyu_zfy6bhwmu",nocase; classtype:trojan-activity; sid:100004195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o",nocase; classtype:trojan-activity; sid:100004196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21226&authkey=adho6klfkjflaqk",nocase; classtype:trojan-activity; sid:100004197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21234&authkey=abhyu_zfy6bhwmu",nocase; classtype:trojan-activity; sid:100004198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c!115&authkey=adbcrakskolznjq",nocase; classtype:trojan-activity; sid:100004199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c%21115&authkey=adbcrakskolznjq",nocase; classtype:trojan-activity; sid:100004200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c%21116&authkey=anenotuhbsni0zu",nocase; classtype:trojan-activity; sid:100004201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22",nocase; classtype:trojan-activity; sid:100004202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100004203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100004204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100004205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100004206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc",nocase; classtype:trojan-activity; sid:100004207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu",nocase; classtype:trojan-activity; sid:100004208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fd67fafc46d3c687&resid=fd67fafc46d3c687%21473&authkey=aoid_cp-jgffqvm",nocase; classtype:trojan-activity; sid:100004209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm",nocase; classtype:trojan-activity; sid:100004210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w",nocase; classtype:trojan-activity; sid:100004211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm",nocase; classtype:trojan-activity; sid:100004212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21848&authkey=ag1_e421v-t5r9w",nocase; classtype:trojan-activity; sid:100004213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw",nocase; classtype:trojan-activity; sid:100004214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!198&authkey=amg468jpljbyyky",nocase; classtype:trojan-activity; sid:100004215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21198&authkey=amg468jpljbyyky",nocase; classtype:trojan-activity; sid:100004216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100004217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100004218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100004219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100004220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100004221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100004222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg",nocase; classtype:trojan-activity; sid:100004223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100004224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm",nocase; classtype:trojan-activity; sid:100004225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100004226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paste.ee",nocase; http_uri; content:"/r/a39ev",nocase; classtype:trojan-activity; sid:100004227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/77jhk0iw",nocase; classtype:trojan-activity; sid:100004228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/89hkc7wb",nocase; classtype:trojan-activity; sid:100004229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/yqvsvlvq",nocase; classtype:trojan-activity; sid:100004230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pierreconsulting.info",nocase; http_uri; content:"/wp-admin/llc/mwcacs65xienqdp/",nocase; classtype:trojan-activity; sid:100004231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pioneiraagronegocio.com.br",nocase; http_uri; content:"/bayesian-forecasting-amj5e/s5hqmf6/",nocase; classtype:trojan-activity; sid:100004232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skoda22.jpg",nocase; classtype:trojan-activity; sid:100004233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg",nocase; classtype:trojan-activity; sid:100004234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qjbutterflyevents.co.za",nocase; http_uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/",nocase; classtype:trojan-activity; sid:100004235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/dhlshipmentawb80326979402.ace",nocase; classtype:trojan-activity; sid:100004236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/maersk-bl+draft-copy-shipping-documents.ace",nocase; classtype:trojan-activity; sid:100004237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/po+for+april+shipment.ace",nocase; classtype:trojan-activity; sid:100004238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"racisa.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/zenar.exe",nocase; classtype:trojan-activity; sid:100004239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll",nocase; classtype:trojan-activity; sid:100004240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe",nocase; classtype:trojan-activity; sid:100004241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe",nocase; classtype:trojan-activity; sid:100004242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe",nocase; classtype:trojan-activity; sid:100004243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe",nocase; classtype:trojan-activity; sid:100004244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar",nocase; classtype:trojan-activity; sid:100004245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/myqseeaccount/one/main/one.htm",nocase; classtype:trojan-activity; sid:100004246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp",nocase; classtype:trojan-activity; sid:100004247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe",nocase; classtype:trojan-activity; sid:100004248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe",nocase; classtype:trojan-activity; sid:100004249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/tennc/webshell/master/other/small_shell.txt",nocase; classtype:trojan-activity; sid:100004250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.yeshen.com",nocase; http_uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe",nocase; classtype:trojan-activity; sid:100004251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sendspace.com",nocase; http_uri; content:"/pro/dl/q05z91",nocase; classtype:trojan-activity; sid:100004252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shribharatvatika.com",nocase; http_uri; content:"/ey4lpx8rx.zip",nocase; classtype:trojan-activity; sid:100004253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sites.google.com",nocase; http_uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0",nocase; classtype:trojan-activity; sid:100004254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt",nocase; classtype:trojan-activity; sid:100004255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt",nocase; classtype:trojan-activity; sid:100004256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt",nocase; classtype:trojan-activity; sid:100004257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt",nocase; classtype:trojan-activity; sid:100004258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt",nocase; classtype:trojan-activity; sid:100004259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt",nocase; classtype:trojan-activity; sid:100004260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt",nocase; classtype:trojan-activity; sid:100004261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg",nocase; classtype:trojan-activity; sid:100004262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt",nocase; classtype:trojan-activity; sid:100004263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technologydistilled.com",nocase; http_uri; content:"/a-nurse-ss8d9/z/",nocase; classtype:trojan-activity; sid:100004264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsrv4.ws",nocase; http_uri; content:"/23.exe",nocase; classtype:trojan-activity; sid:100004265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"users.skynet.be",nocase; http_uri; content:"/crisanar/defis/jek_crackme1.7.zip",nocase; classtype:trojan-activity; sid:100004266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/amowvegfrt9ja/",nocase; classtype:trojan-activity; sid:100004267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/",nocase; classtype:trojan-activity; sid:100004268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100004269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100004270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe",nocase; classtype:trojan-activity; sid:100004271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb%5efr_ouverture.exe",nocase; classtype:trojan-activity; sid:100004272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb^fr_ouverture.exe",nocase; classtype:trojan-activity; sid:100004273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe",nocase; classtype:trojan-activity; sid:100004274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/151_155/tidex_-_short_stuff.exe",nocase; classtype:trojan-activity; sid:100004275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikileaks.org",nocase; http_uri; content:"/syria-files/attach/222/222051_instruction.zip",nocase; classtype:trojan-activity; sid:100004276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yp.hnggzyjy.cn",nocase; http_uri; content:"/common/yz.vbs",nocase; classtype:trojan-activity; sid:100004277; rev:1;) diff --git a/urlhaus-filter-suricata-online.rules b/urlhaus-filter-suricata-online.rules index 8651bfef..105d6643 100644 --- a/urlhaus-filter-suricata-online.rules +++ b/urlhaus-filter-suricata-online.rules @@ -1,5 +1,5 @@ # Title: Online Malicious URL Suricata Ruleset -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -7,40 +7,40 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"0-24bpautomentes.hu"; classtype:trojan-activity; sid:100000001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"0cl.sldov.ru"; classtype:trojan-activity; sid:100000002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.11.234.99"; classtype:trojan-activity; sid:100000003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.222.196.60"; classtype:trojan-activity; sid:100000004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.245.4.163"; classtype:trojan-activity; sid:100000005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.107"; classtype:trojan-activity; sid:100000006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.109"; classtype:trojan-activity; sid:100000007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.113"; classtype:trojan-activity; sid:100000008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.127"; classtype:trojan-activity; sid:100000009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.134"; classtype:trojan-activity; sid:100000010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.138"; classtype:trojan-activity; sid:100000011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.14"; classtype:trojan-activity; sid:100000012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.16"; classtype:trojan-activity; sid:100000013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.186.151.219"; classtype:trojan-activity; sid:100000004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.222.196.60"; classtype:trojan-activity; sid:100000005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.245.4.163"; classtype:trojan-activity; sid:100000006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.107"; classtype:trojan-activity; sid:100000007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.109"; classtype:trojan-activity; sid:100000008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.113"; classtype:trojan-activity; sid:100000009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.127"; classtype:trojan-activity; sid:100000010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.134"; classtype:trojan-activity; sid:100000011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.138"; classtype:trojan-activity; sid:100000012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.14"; classtype:trojan-activity; sid:100000013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.165"; classtype:trojan-activity; sid:100000014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.20"; classtype:trojan-activity; sid:100000015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.228"; classtype:trojan-activity; sid:100000016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.232"; classtype:trojan-activity; sid:100000017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.234"; classtype:trojan-activity; sid:100000018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.237"; classtype:trojan-activity; sid:100000019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.245"; classtype:trojan-activity; sid:100000020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.249"; classtype:trojan-activity; sid:100000021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.25"; classtype:trojan-activity; sid:100000022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.38"; classtype:trojan-activity; sid:100000023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.41"; classtype:trojan-activity; sid:100000024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.43"; classtype:trojan-activity; sid:100000025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.45"; classtype:trojan-activity; sid:100000026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.56"; classtype:trojan-activity; sid:100000027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.63"; classtype:trojan-activity; sid:100000028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.69"; classtype:trojan-activity; sid:100000029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.8"; classtype:trojan-activity; sid:100000030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.80"; classtype:trojan-activity; sid:100000031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.94"; classtype:trojan-activity; sid:100000032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.98"; classtype:trojan-activity; sid:100000033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.10"; classtype:trojan-activity; sid:100000034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.103"; classtype:trojan-activity; sid:100000035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.105"; classtype:trojan-activity; sid:100000036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.109"; classtype:trojan-activity; sid:100000037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.234"; classtype:trojan-activity; sid:100000017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.237"; classtype:trojan-activity; sid:100000018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.245"; classtype:trojan-activity; sid:100000019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.249"; classtype:trojan-activity; sid:100000020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.25"; classtype:trojan-activity; sid:100000021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.38"; classtype:trojan-activity; sid:100000022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.41"; classtype:trojan-activity; sid:100000023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.43"; classtype:trojan-activity; sid:100000024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.45"; classtype:trojan-activity; sid:100000025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.56"; classtype:trojan-activity; sid:100000026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.63"; classtype:trojan-activity; sid:100000027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.69"; classtype:trojan-activity; sid:100000028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.8"; classtype:trojan-activity; sid:100000029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.80"; classtype:trojan-activity; sid:100000030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.94"; classtype:trojan-activity; sid:100000031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.98"; classtype:trojan-activity; sid:100000032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.10"; classtype:trojan-activity; sid:100000033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.103"; classtype:trojan-activity; sid:100000034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.105"; classtype:trojan-activity; sid:100000035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.109"; classtype:trojan-activity; sid:100000036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.126"; classtype:trojan-activity; sid:100000037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.127"; classtype:trojan-activity; sid:100000038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.130"; classtype:trojan-activity; sid:100000039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.146"; classtype:trojan-activity; sid:100000040; rev:1;) @@ -78,4328 +78,4206 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.73.131.78"; classtype:trojan-activity; sid:100000072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.75.157.99"; classtype:trojan-activity; sid:100000073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.75.167.213"; classtype:trojan-activity; sid:100000074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.99.94.15"; classtype:trojan-activity; sid:100000075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.130.115.14"; classtype:trojan-activity; sid:100000076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.141.240.139"; classtype:trojan-activity; sid:100000077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.113.99.79"; classtype:trojan-activity; sid:100000078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.125.218.107"; classtype:trojan-activity; sid:100000079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.136.82.50"; classtype:trojan-activity; sid:100000080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.141.138.118"; classtype:trojan-activity; sid:100000081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.141.138.12"; classtype:trojan-activity; sid:100000082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.146.174.208"; classtype:trojan-activity; sid:100000083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.16.145.25"; classtype:trojan-activity; sid:100000084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.204.168.34"; classtype:trojan-activity; sid:100000085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.217.215.21"; classtype:trojan-activity; sid:100000086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.224.200.146"; classtype:trojan-activity; sid:100000087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.224.200.40"; classtype:trojan-activity; sid:100000088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.227.118.129"; classtype:trojan-activity; sid:100000089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.238.228.4"; classtype:trojan-activity; sid:100000090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.240.249.121"; classtype:trojan-activity; sid:100000091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.4.117.26"; classtype:trojan-activity; sid:100000092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.70.160.51"; classtype:trojan-activity; sid:100000093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.79.112.254"; classtype:trojan-activity; sid:100000094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.82.98.170"; classtype:trojan-activity; sid:100000095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.240.130"; classtype:trojan-activity; sid:100000096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.12"; classtype:trojan-activity; sid:100000097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.13"; classtype:trojan-activity; sid:100000098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.14"; classtype:trojan-activity; sid:100000099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.16"; classtype:trojan-activity; sid:100000100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.17"; classtype:trojan-activity; sid:100000101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.27"; classtype:trojan-activity; sid:100000102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.3"; classtype:trojan-activity; sid:100000103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.46"; classtype:trojan-activity; sid:100000104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.90"; classtype:trojan-activity; sid:100000105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.95"; classtype:trojan-activity; sid:100000106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.97.184.180"; classtype:trojan-activity; sid:100000107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.168.98.159"; classtype:trojan-activity; sid:100000108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.184.75.123"; classtype:trojan-activity; sid:100000109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.206.93.94"; classtype:trojan-activity; sid:100000110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.33.52.85"; classtype:trojan-activity; sid:100000111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.61.86.37"; classtype:trojan-activity; sid:100000112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.1.111.91"; classtype:trojan-activity; sid:100000113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.104.172.178"; classtype:trojan-activity; sid:100000114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.104.193.155"; classtype:trojan-activity; sid:100000115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.105.33.43"; classtype:trojan-activity; sid:100000116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.165.234"; classtype:trojan-activity; sid:100000117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.193.132"; classtype:trojan-activity; sid:100000118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.249.148"; classtype:trojan-activity; sid:100000119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.155.54"; classtype:trojan-activity; sid:100000120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.219.80"; classtype:trojan-activity; sid:100000121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.250.107"; classtype:trojan-activity; sid:100000122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.61.139"; classtype:trojan-activity; sid:100000123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.197.135"; classtype:trojan-activity; sid:100000124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.31.130"; classtype:trojan-activity; sid:100000125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.33.48"; classtype:trojan-activity; sid:100000126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.181.136.96"; classtype:trojan-activity; sid:100000127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.189.8.75"; classtype:trojan-activity; sid:100000128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.194.242.170"; classtype:trojan-activity; sid:100000129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.219.185.75"; classtype:trojan-activity; sid:100000130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.220.119.25"; classtype:trojan-activity; sid:100000131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.221.96.202"; classtype:trojan-activity; sid:100000132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.201.37"; classtype:trojan-activity; sid:100000133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.250.48"; classtype:trojan-activity; sid:100000134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.55.199.65"; classtype:trojan-activity; sid:100000135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.124.90.229"; classtype:trojan-activity; sid:100000136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.233.196.232"; classtype:trojan-activity; sid:100000137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.235.7.228"; classtype:trojan-activity; sid:100000138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.86.85.253"; classtype:trojan-activity; sid:100000139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.102"; classtype:trojan-activity; sid:100000140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.230"; classtype:trojan-activity; sid:100000141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.127.90"; classtype:trojan-activity; sid:100000142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.57.246"; classtype:trojan-activity; sid:100000143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.99.37.97"; classtype:trojan-activity; sid:100000144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.10.58.38"; classtype:trojan-activity; sid:100000145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.14.58.190"; classtype:trojan-activity; sid:100000146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.187.229.182"; classtype:trojan-activity; sid:100000147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.228.190.50"; classtype:trojan-activity; sid:100000148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.228.195.46"; classtype:trojan-activity; sid:100000149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.241.119.168"; classtype:trojan-activity; sid:100000150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.124.254"; classtype:trojan-activity; sid:100000151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.251.194"; classtype:trojan-activity; sid:100000152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.251.10.18"; classtype:trojan-activity; sid:100000153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.150.248"; classtype:trojan-activity; sid:100000154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.213.198"; classtype:trojan-activity; sid:100000155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.130.115.14"; classtype:trojan-activity; sid:100000075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.141.240.139"; classtype:trojan-activity; sid:100000076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.113.99.79"; classtype:trojan-activity; sid:100000077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.125.218.107"; classtype:trojan-activity; sid:100000078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.141.138.118"; classtype:trojan-activity; sid:100000079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.141.138.12"; classtype:trojan-activity; sid:100000080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.146.174.208"; classtype:trojan-activity; sid:100000081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.16.145.25"; classtype:trojan-activity; sid:100000082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.204.168.34"; classtype:trojan-activity; sid:100000083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.217.215.21"; classtype:trojan-activity; sid:100000084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.224.200.146"; classtype:trojan-activity; sid:100000085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.224.200.40"; classtype:trojan-activity; sid:100000086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.237.21.36"; classtype:trojan-activity; sid:100000087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.238.228.4"; classtype:trojan-activity; sid:100000088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.240.249.121"; classtype:trojan-activity; sid:100000089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.4.117.26"; classtype:trojan-activity; sid:100000090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.70.160.51"; classtype:trojan-activity; sid:100000091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.82.98.170"; classtype:trojan-activity; sid:100000092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.240.130"; classtype:trojan-activity; sid:100000093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.12"; classtype:trojan-activity; sid:100000094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.13"; classtype:trojan-activity; sid:100000095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.14"; classtype:trojan-activity; sid:100000096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.16"; classtype:trojan-activity; sid:100000097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.17"; classtype:trojan-activity; sid:100000098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.27"; classtype:trojan-activity; sid:100000099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.3"; classtype:trojan-activity; sid:100000100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.46"; classtype:trojan-activity; sid:100000101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.90"; classtype:trojan-activity; sid:100000102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.95"; classtype:trojan-activity; sid:100000103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.97.184.180"; classtype:trojan-activity; sid:100000104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.168.98.159"; classtype:trojan-activity; sid:100000105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.184.75.123"; classtype:trojan-activity; sid:100000106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.206.93.94"; classtype:trojan-activity; sid:100000107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.33.52.85"; classtype:trojan-activity; sid:100000108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.61.86.37"; classtype:trojan-activity; sid:100000109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.1.111.91"; classtype:trojan-activity; sid:100000110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.104.172.178"; classtype:trojan-activity; sid:100000111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.104.193.155"; classtype:trojan-activity; sid:100000112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.105.33.43"; classtype:trojan-activity; sid:100000113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.165.234"; classtype:trojan-activity; sid:100000114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.193.132"; classtype:trojan-activity; sid:100000115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.249.148"; classtype:trojan-activity; sid:100000116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.155.54"; classtype:trojan-activity; sid:100000117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.219.80"; classtype:trojan-activity; sid:100000118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.250.107"; classtype:trojan-activity; sid:100000119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.61.139"; classtype:trojan-activity; sid:100000120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.197.135"; classtype:trojan-activity; sid:100000121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.31.130"; classtype:trojan-activity; sid:100000122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.33.48"; classtype:trojan-activity; sid:100000123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.181.136.96"; classtype:trojan-activity; sid:100000124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.189.8.75"; classtype:trojan-activity; sid:100000125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.194.242.170"; classtype:trojan-activity; sid:100000126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.219.185.75"; classtype:trojan-activity; sid:100000127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.220.119.25"; classtype:trojan-activity; sid:100000128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.221.96.202"; classtype:trojan-activity; sid:100000129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.201.37"; classtype:trojan-activity; sid:100000130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.250.48"; classtype:trojan-activity; sid:100000131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.55.199.65"; classtype:trojan-activity; sid:100000132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.124.90.229"; classtype:trojan-activity; sid:100000133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.233.196.232"; classtype:trojan-activity; sid:100000134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.235.7.228"; classtype:trojan-activity; sid:100000135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.248.58.238"; classtype:trojan-activity; sid:100000136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.86.85.253"; classtype:trojan-activity; sid:100000137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.102"; classtype:trojan-activity; sid:100000138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.230"; classtype:trojan-activity; sid:100000139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.127.90"; classtype:trojan-activity; sid:100000140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.57.246"; classtype:trojan-activity; sid:100000141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.99.37.97"; classtype:trojan-activity; sid:100000142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.10.58.38"; classtype:trojan-activity; sid:100000143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.14.58.190"; classtype:trojan-activity; sid:100000144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.187.229.182"; classtype:trojan-activity; sid:100000145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.228.190.50"; classtype:trojan-activity; sid:100000146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.228.195.46"; classtype:trojan-activity; sid:100000147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.241.119.168"; classtype:trojan-activity; sid:100000148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.124.254"; classtype:trojan-activity; sid:100000149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.175.141"; classtype:trojan-activity; sid:100000150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.251.194"; classtype:trojan-activity; sid:100000151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.251.10.18"; classtype:trojan-activity; sid:100000152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.150.248"; classtype:trojan-activity; sid:100000153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.213.198"; classtype:trojan-activity; sid:100000154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.51.112"; classtype:trojan-activity; sid:100000155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.255.101.184"; classtype:trojan-activity; sid:100000156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.255.167.147"; classtype:trojan-activity; sid:100000157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.145.127"; classtype:trojan-activity; sid:100000158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.208.21"; classtype:trojan-activity; sid:100000159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.221.77"; classtype:trojan-activity; sid:100000160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.223.92"; classtype:trojan-activity; sid:100000161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.225.24"; classtype:trojan-activity; sid:100000162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.233.147"; classtype:trojan-activity; sid:100000163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.235.57"; classtype:trojan-activity; sid:100000164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.4.2"; classtype:trojan-activity; sid:100000165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110fss.net"; classtype:trojan-activity; sid:100000166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.111.207"; classtype:trojan-activity; sid:100000167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.41.173"; classtype:trojan-activity; sid:100000168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.88.61"; classtype:trojan-activity; sid:100000169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.119.245.114"; classtype:trojan-activity; sid:100000170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.125.67.125"; classtype:trojan-activity; sid:100000171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.165.21.195"; classtype:trojan-activity; sid:100000172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.165.248.134"; classtype:trojan-activity; sid:100000173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.166.236.191"; classtype:trojan-activity; sid:100000174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.167.151.156"; classtype:trojan-activity; sid:100000175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.85.71"; classtype:trojan-activity; sid:100000176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.86.31"; classtype:trojan-activity; sid:100000177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.172.57.20"; classtype:trojan-activity; sid:100000178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.182.235.252"; classtype:trojan-activity; sid:100000179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.171.111"; classtype:trojan-activity; sid:100000180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.177.85"; classtype:trojan-activity; sid:100000181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.23.84"; classtype:trojan-activity; sid:100000182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.230.136"; classtype:trojan-activity; sid:100000183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.27.9"; classtype:trojan-activity; sid:100000184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.49.223"; classtype:trojan-activity; sid:100000185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.122"; classtype:trojan-activity; sid:100000186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.66"; classtype:trojan-activity; sid:100000187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.104.141"; classtype:trojan-activity; sid:100000188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.104.15"; classtype:trojan-activity; sid:100000189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.128"; classtype:trojan-activity; sid:100000190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.19"; classtype:trojan-activity; sid:100000191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.222"; classtype:trojan-activity; sid:100000192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.223"; classtype:trojan-activity; sid:100000193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.226"; classtype:trojan-activity; sid:100000194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.228"; classtype:trojan-activity; sid:100000195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.26.243"; classtype:trojan-activity; sid:100000196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.61.52.53"; classtype:trojan-activity; sid:100000197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.108.184"; classtype:trojan-activity; sid:100000198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.31.175"; classtype:trojan-activity; sid:100000199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.133.222.151"; classtype:trojan-activity; sid:100000200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.147.92.51"; classtype:trojan-activity; sid:100000201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.159.108.96"; classtype:trojan-activity; sid:100000202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.163.200.217"; classtype:trojan-activity; sid:100000203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.124.75"; classtype:trojan-activity; sid:100000204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.233.9"; classtype:trojan-activity; sid:100000205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.210.211"; classtype:trojan-activity; sid:100000206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.96.252"; classtype:trojan-activity; sid:100000207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.187.91.117"; classtype:trojan-activity; sid:100000208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.214.127.42"; classtype:trojan-activity; sid:100000209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.187.19"; classtype:trojan-activity; sid:100000210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.236.77"; classtype:trojan-activity; sid:100000211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.239.126"; classtype:trojan-activity; sid:100000212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.43.27"; classtype:trojan-activity; sid:100000213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.118.229"; classtype:trojan-activity; sid:100000214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.202.111"; classtype:trojan-activity; sid:100000215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.67.193"; classtype:trojan-activity; sid:100000216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.180.95"; classtype:trojan-activity; sid:100000217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.79.114"; classtype:trojan-activity; sid:100000218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.79.137"; classtype:trojan-activity; sid:100000219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.178.109"; classtype:trojan-activity; sid:100000220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.188.28"; classtype:trojan-activity; sid:100000221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.230.168.103"; classtype:trojan-activity; sid:100000222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.218.202"; classtype:trojan-activity; sid:100000223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.235.149.73"; classtype:trojan-activity; sid:100000224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.235.188.86"; classtype:trojan-activity; sid:100000225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.171.69"; classtype:trojan-activity; sid:100000226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.141.241"; classtype:trojan-activity; sid:100000227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.144.226"; classtype:trojan-activity; sid:100000228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.197.144"; classtype:trojan-activity; sid:100000229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.209.30"; classtype:trojan-activity; sid:100000230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.75.157"; classtype:trojan-activity; sid:100000231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.143.135"; classtype:trojan-activity; sid:100000232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.17.120"; classtype:trojan-activity; sid:100000233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.190.207"; classtype:trojan-activity; sid:100000234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.227.228"; classtype:trojan-activity; sid:100000235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.39.2"; classtype:trojan-activity; sid:100000236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.73.181"; classtype:trojan-activity; sid:100000237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.240.216.17"; classtype:trojan-activity; sid:100000238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.152.44"; classtype:trojan-activity; sid:100000239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.2.247"; classtype:trojan-activity; sid:100000240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.243.80"; classtype:trojan-activity; sid:100000241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.12.89"; classtype:trojan-activity; sid:100000242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.8.24"; classtype:trojan-activity; sid:100000243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.126.58"; classtype:trojan-activity; sid:100000244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.162.50"; classtype:trojan-activity; sid:100000245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.180.49"; classtype:trojan-activity; sid:100000246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.51.77"; classtype:trojan-activity; sid:100000247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.100.14"; classtype:trojan-activity; sid:100000248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.121.39"; classtype:trojan-activity; sid:100000249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.16.222"; classtype:trojan-activity; sid:100000250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.191.118"; classtype:trojan-activity; sid:100000251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.214.146"; classtype:trojan-activity; sid:100000252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.240.226"; classtype:trojan-activity; sid:100000253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.25.42"; classtype:trojan-activity; sid:100000254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.8.112"; classtype:trojan-activity; sid:100000255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.81.173"; classtype:trojan-activity; sid:100000256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.82.122"; classtype:trojan-activity; sid:100000257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.148.90"; classtype:trojan-activity; sid:100000258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.179.239"; classtype:trojan-activity; sid:100000259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.197.164"; classtype:trojan-activity; sid:100000260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.109.217"; classtype:trojan-activity; sid:100000261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.118.157"; classtype:trojan-activity; sid:100000262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.26.129"; classtype:trojan-activity; sid:100000263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.79.98"; classtype:trojan-activity; sid:100000264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.250.102.173"; classtype:trojan-activity; sid:100000265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.250.57.99"; classtype:trojan-activity; sid:100000266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.218.210"; classtype:trojan-activity; sid:100000267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.136.84"; classtype:trojan-activity; sid:100000268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.196.17"; classtype:trojan-activity; sid:100000269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.212.122"; classtype:trojan-activity; sid:100000270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.221.244"; classtype:trojan-activity; sid:100000271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.239.103"; classtype:trojan-activity; sid:100000272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.254.208.123"; classtype:trojan-activity; sid:100000273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.254.32.5"; classtype:trojan-activity; sid:100000274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.38.10"; classtype:trojan-activity; sid:100000275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.6.129"; classtype:trojan-activity; sid:100000276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.8.235"; classtype:trojan-activity; sid:100000277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.121.163"; classtype:trojan-activity; sid:100000278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.108"; classtype:trojan-activity; sid:100000279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.111"; classtype:trojan-activity; sid:100000280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.117"; classtype:trojan-activity; sid:100000281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.122"; classtype:trojan-activity; sid:100000282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.124"; classtype:trojan-activity; sid:100000283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.131"; classtype:trojan-activity; sid:100000284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.132"; classtype:trojan-activity; sid:100000285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.133"; classtype:trojan-activity; sid:100000286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.138"; classtype:trojan-activity; sid:100000287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.139"; classtype:trojan-activity; sid:100000288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.142"; classtype:trojan-activity; sid:100000289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.143"; classtype:trojan-activity; sid:100000290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.146"; classtype:trojan-activity; sid:100000291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.149"; classtype:trojan-activity; sid:100000292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.150"; classtype:trojan-activity; sid:100000293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.151"; classtype:trojan-activity; sid:100000294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.158"; classtype:trojan-activity; sid:100000295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.160"; classtype:trojan-activity; sid:100000296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.162"; classtype:trojan-activity; sid:100000297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.163"; classtype:trojan-activity; sid:100000298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.165"; classtype:trojan-activity; sid:100000299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.171"; classtype:trojan-activity; sid:100000300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.174"; classtype:trojan-activity; sid:100000301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.175"; classtype:trojan-activity; sid:100000302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.177"; classtype:trojan-activity; sid:100000303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.178"; classtype:trojan-activity; sid:100000304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.179"; classtype:trojan-activity; sid:100000305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.71"; classtype:trojan-activity; sid:100000306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.127.155"; classtype:trojan-activity; sid:100000307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.182"; classtype:trojan-activity; sid:100000308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.23"; classtype:trojan-activity; sid:100000309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.85.113"; classtype:trojan-activity; sid:100000310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.87.213"; classtype:trojan-activity; sid:100000311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.88.116"; classtype:trojan-activity; sid:100000312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.91.212"; classtype:trojan-activity; sid:100000313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.133"; classtype:trojan-activity; sid:100000314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.158"; classtype:trojan-activity; sid:100000315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.164"; classtype:trojan-activity; sid:100000316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.168"; classtype:trojan-activity; sid:100000317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.177"; classtype:trojan-activity; sid:100000318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.188"; classtype:trojan-activity; sid:100000319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.190"; classtype:trojan-activity; sid:100000320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.211"; classtype:trojan-activity; sid:100000321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.219"; classtype:trojan-activity; sid:100000322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.229"; classtype:trojan-activity; sid:100000323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.230"; classtype:trojan-activity; sid:100000324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.247"; classtype:trojan-activity; sid:100000325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.57"; classtype:trojan-activity; sid:100000326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.90"; classtype:trojan-activity; sid:100000327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.91"; classtype:trojan-activity; sid:100000328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.31"; classtype:trojan-activity; sid:100000329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.36"; classtype:trojan-activity; sid:100000330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.37"; classtype:trojan-activity; sid:100000331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.38"; classtype:trojan-activity; sid:100000332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.41"; classtype:trojan-activity; sid:100000333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.43"; classtype:trojan-activity; sid:100000334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.48"; classtype:trojan-activity; sid:100000335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.52"; classtype:trojan-activity; sid:100000336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.35.237"; classtype:trojan-activity; sid:100000337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.38.98"; classtype:trojan-activity; sid:100000338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.103"; classtype:trojan-activity; sid:100000339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.118"; classtype:trojan-activity; sid:100000340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.121"; classtype:trojan-activity; sid:100000341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.124"; classtype:trojan-activity; sid:100000342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.136"; classtype:trojan-activity; sid:100000343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.52"; classtype:trojan-activity; sid:100000344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.240.239"; classtype:trojan-activity; sid:100000345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.82.160"; classtype:trojan-activity; sid:100000346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.87.98"; classtype:trojan-activity; sid:100000347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.224.79"; classtype:trojan-activity; sid:100000348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.65.53.175"; classtype:trojan-activity; sid:100000349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.49"; classtype:trojan-activity; sid:100000350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.53"; classtype:trojan-activity; sid:100000351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.112"; classtype:trojan-activity; sid:100000352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.84"; classtype:trojan-activity; sid:100000353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.231.35"; classtype:trojan-activity; sid:100000354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.78.45.158"; classtype:trojan-activity; sid:100000355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.117.32"; classtype:trojan-activity; sid:100000356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.118.16"; classtype:trojan-activity; sid:100000357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.127.91"; classtype:trojan-activity; sid:100000358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.207.144"; classtype:trojan-activity; sid:100000359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.215.101"; classtype:trojan-activity; sid:100000360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.146.253"; classtype:trojan-activity; sid:100000361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.18.255"; classtype:trojan-activity; sid:100000362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.224.139"; classtype:trojan-activity; sid:100000363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.93.29.211"; classtype:trojan-activity; sid:100000364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.11.95.254"; classtype:trojan-activity; sid:100000365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.144.140"; classtype:trojan-activity; sid:100000366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.122.238.68"; classtype:trojan-activity; sid:100000367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.161.58.249"; classtype:trojan-activity; sid:100000368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.161.78.185"; classtype:trojan-activity; sid:100000369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.172.250.35"; classtype:trojan-activity; sid:100000370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.195.163.26"; classtype:trojan-activity; sid:100000371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.226.42.250"; classtype:trojan-activity; sid:100000372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.194.172"; classtype:trojan-activity; sid:100000373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.35.229"; classtype:trojan-activity; sid:100000374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.211.131"; classtype:trojan-activity; sid:100000375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.254.169.251"; classtype:trojan-activity; sid:100000376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.128.133"; classtype:trojan-activity; sid:100000377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.136.39"; classtype:trojan-activity; sid:100000378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.154.21"; classtype:trojan-activity; sid:100000379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.191.47"; classtype:trojan-activity; sid:100000380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.61.204.205"; classtype:trojan-activity; sid:100000381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.87.174.63"; classtype:trojan-activity; sid:100000382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.87.175.135"; classtype:trojan-activity; sid:100000383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.89.42.50"; classtype:trojan-activity; sid:100000384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.89.43.185"; classtype:trojan-activity; sid:100000385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.90.26.136"; classtype:trojan-activity; sid:100000386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.199.204.37"; classtype:trojan-activity; sid:100000387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.200.154.181"; classtype:trojan-activity; sid:100000388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.224.203.128"; classtype:trojan-activity; sid:100000389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.226.100.56"; classtype:trojan-activity; sid:100000390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.228.205.101"; classtype:trojan-activity; sid:100000391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.229.165.194"; classtype:trojan-activity; sid:100000392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.235.115.236"; classtype:trojan-activity; sid:100000393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.30.54.64"; classtype:trojan-activity; sid:100000394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.32.237.100"; classtype:trojan-activity; sid:100000395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.79.172.42"; classtype:trojan-activity; sid:100000396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.165.216.112"; classtype:trojan-activity; sid:100000397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.201.38.185"; classtype:trojan-activity; sid:100000398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.42.47.36"; classtype:trojan-activity; sid:100000399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.204.56"; classtype:trojan-activity; sid:100000400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.21.56"; classtype:trojan-activity; sid:100000401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.125.55"; classtype:trojan-activity; sid:100000402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.18.65"; classtype:trojan-activity; sid:100000403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.144.42"; classtype:trojan-activity; sid:100000404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.145.147"; classtype:trojan-activity; sid:100000405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.153.194"; classtype:trojan-activity; sid:100000406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.190.144"; classtype:trojan-activity; sid:100000407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.60.129"; classtype:trojan-activity; sid:100000408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.131.242"; classtype:trojan-activity; sid:100000409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.133.96"; classtype:trojan-activity; sid:100000410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.144.213"; classtype:trojan-activity; sid:100000411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.159.132"; classtype:trojan-activity; sid:100000412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.187.173"; classtype:trojan-activity; sid:100000413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.132.140"; classtype:trojan-activity; sid:100000414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.165.147"; classtype:trojan-activity; sid:100000415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.240.217"; classtype:trojan-activity; sid:100000416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.255.194"; classtype:trojan-activity; sid:100000417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.118.201"; classtype:trojan-activity; sid:100000418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.62.26.39"; classtype:trojan-activity; sid:100000419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.73.3.11"; classtype:trojan-activity; sid:100000420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.92.174.231"; classtype:trojan-activity; sid:100000421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.124.219.2"; classtype:trojan-activity; sid:100000422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.132.151.60"; classtype:trojan-activity; sid:100000423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.206.164.46"; classtype:trojan-activity; sid:100000424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.211.100.26"; classtype:trojan-activity; sid:100000425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.212.132.119"; classtype:trojan-activity; sid:100000426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.212.142.215"; classtype:trojan-activity; sid:100000427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.196.49.249"; classtype:trojan-activity; sid:100000428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.196.50.107"; classtype:trojan-activity; sid:100000429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.138"; classtype:trojan-activity; sid:100000430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.5"; classtype:trojan-activity; sid:100000431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.210.52"; classtype:trojan-activity; sid:100000432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.236.14"; classtype:trojan-activity; sid:100000433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.243.40"; classtype:trojan-activity; sid:100000434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.200.76.54"; classtype:trojan-activity; sid:100000435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.26.110.103"; classtype:trojan-activity; sid:100000436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.113.146"; classtype:trojan-activity; sid:100000437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.195.140"; classtype:trojan-activity; sid:100000438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.53.15"; classtype:trojan-activity; sid:100000439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.86.105.110"; classtype:trojan-activity; sid:100000440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.104.35"; classtype:trojan-activity; sid:100000441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.157.64"; classtype:trojan-activity; sid:100000442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.7.132"; classtype:trojan-activity; sid:100000443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.32.74"; classtype:trojan-activity; sid:100000444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.5.149"; classtype:trojan-activity; sid:100000445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.72.141"; classtype:trojan-activity; sid:100000446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.12.130"; classtype:trojan-activity; sid:100000447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.128.147"; classtype:trojan-activity; sid:100000448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.208.215"; classtype:trojan-activity; sid:100000449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.209.108"; classtype:trojan-activity; sid:100000450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.214.72"; classtype:trojan-activity; sid:100000451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.88.146"; classtype:trojan-activity; sid:100000452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.150"; classtype:trojan-activity; sid:100000453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.6"; classtype:trojan-activity; sid:100000454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.221.162"; classtype:trojan-activity; sid:100000455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.63.194"; classtype:trojan-activity; sid:100000456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.65.93"; classtype:trojan-activity; sid:100000457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.42.125.246"; classtype:trojan-activity; sid:100000458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.43.180.33"; classtype:trojan-activity; sid:100000459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.125.92"; classtype:trojan-activity; sid:100000460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.218.157"; classtype:trojan-activity; sid:100000461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.50.203"; classtype:trojan-activity; sid:100000462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.58.82"; classtype:trojan-activity; sid:100000463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.96.11"; classtype:trojan-activity; sid:100000464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.83.79.43"; classtype:trojan-activity; sid:100000465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.91.24.27"; classtype:trojan-activity; sid:100000466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.179.164"; classtype:trojan-activity; sid:100000467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.183.235"; classtype:trojan-activity; sid:100000468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.239.217"; classtype:trojan-activity; sid:100000469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.108.161.25"; classtype:trojan-activity; sid:100000470; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.112.185.232"; classtype:trojan-activity; sid:100000471; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.119.63.145"; classtype:trojan-activity; sid:100000472; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.14.143.145"; classtype:trojan-activity; sid:100000473; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.147.213.57"; classtype:trojan-activity; sid:100000474; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.163.93.191"; classtype:trojan-activity; sid:100000475; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.18.235"; classtype:trojan-activity; sid:100000476; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.218.229"; classtype:trojan-activity; sid:100000477; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.107.93"; classtype:trojan-activity; sid:100000478; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.163.220"; classtype:trojan-activity; sid:100000479; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.174.63"; classtype:trojan-activity; sid:100000480; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.197.106"; classtype:trojan-activity; sid:100000481; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.241.222"; classtype:trojan-activity; sid:100000482; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.27.77"; classtype:trojan-activity; sid:100000483; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.68.145"; classtype:trojan-activity; sid:100000484; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.170.241"; classtype:trojan-activity; sid:100000485; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.97.6"; classtype:trojan-activity; sid:100000486; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.26.33"; classtype:trojan-activity; sid:100000487; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.177.147.38"; classtype:trojan-activity; sid:100000488; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.248.123"; classtype:trojan-activity; sid:100000489; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.157.219"; classtype:trojan-activity; sid:100000490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.16.149"; classtype:trojan-activity; sid:100000491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.170.212"; classtype:trojan-activity; sid:100000492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.43.1"; classtype:trojan-activity; sid:100000493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.75.8"; classtype:trojan-activity; sid:100000494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.18.38.144"; classtype:trojan-activity; sid:100000495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.106.217"; classtype:trojan-activity; sid:100000496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.108.227"; classtype:trojan-activity; sid:100000497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.108.79"; classtype:trojan-activity; sid:100000498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.33.161"; classtype:trojan-activity; sid:100000499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.94.80"; classtype:trojan-activity; sid:100000500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.119.21"; classtype:trojan-activity; sid:100000501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.124.203"; classtype:trojan-activity; sid:100000502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.182.97.232"; classtype:trojan-activity; sid:100000503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.183.115.103"; classtype:trojan-activity; sid:100000504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.14.112"; classtype:trojan-activity; sid:100000505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.172.199"; classtype:trojan-activity; sid:100000506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.195.161"; classtype:trojan-activity; sid:100000507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.245.61"; classtype:trojan-activity; sid:100000508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.137.195"; classtype:trojan-activity; sid:100000509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.227.244"; classtype:trojan-activity; sid:100000510; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.150.85"; classtype:trojan-activity; sid:100000511; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.187.206"; classtype:trojan-activity; sid:100000512; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.215.221"; classtype:trojan-activity; sid:100000513; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.240.20"; classtype:trojan-activity; sid:100000514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.204.30.144"; classtype:trojan-activity; sid:100000515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.250.129.231"; classtype:trojan-activity; sid:100000516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.105.221"; classtype:trojan-activity; sid:100000517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.14.251"; classtype:trojan-activity; sid:100000518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.131.155"; classtype:trojan-activity; sid:100000519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.46"; classtype:trojan-activity; sid:100000520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.71"; classtype:trojan-activity; sid:100000521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.144.75"; classtype:trojan-activity; sid:100000522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.148.115"; classtype:trojan-activity; sid:100000523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.155.57"; classtype:trojan-activity; sid:100000524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.172.28"; classtype:trojan-activity; sid:100000525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.175.41"; classtype:trojan-activity; sid:100000526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.195.90"; classtype:trojan-activity; sid:100000527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.206.43"; classtype:trojan-activity; sid:100000528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.232.62"; classtype:trojan-activity; sid:100000529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.132.113.2"; classtype:trojan-activity; sid:100000530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.15.69.83"; classtype:trojan-activity; sid:100000531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.6"; classtype:trojan-activity; sid:100000532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.7"; classtype:trojan-activity; sid:100000533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.8"; classtype:trojan-activity; sid:100000534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.9"; classtype:trojan-activity; sid:100000535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.207.39.227"; classtype:trojan-activity; sid:100000536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.25.204.189"; classtype:trojan-activity; sid:100000537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.0.255.173"; classtype:trojan-activity; sid:100000538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.12.153.54"; classtype:trojan-activity; sid:100000539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.142.222.22"; classtype:trojan-activity; sid:100000540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.150.213.110"; classtype:trojan-activity; sid:100000541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.151.248.134"; classtype:trojan-activity; sid:100000542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.180"; classtype:trojan-activity; sid:100000543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.183"; classtype:trojan-activity; sid:100000544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.185"; classtype:trojan-activity; sid:100000545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.186"; classtype:trojan-activity; sid:100000546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.188"; classtype:trojan-activity; sid:100000547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.193"; classtype:trojan-activity; sid:100000548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.201"; classtype:trojan-activity; sid:100000549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.204"; classtype:trojan-activity; sid:100000550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.208"; classtype:trojan-activity; sid:100000551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.209"; classtype:trojan-activity; sid:100000552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.212"; classtype:trojan-activity; sid:100000553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.215"; classtype:trojan-activity; sid:100000554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.233"; classtype:trojan-activity; sid:100000555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.121.243"; classtype:trojan-activity; sid:100000556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.206"; classtype:trojan-activity; sid:100000557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.240"; classtype:trojan-activity; sid:100000558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.127.187"; classtype:trojan-activity; sid:100000559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.99.127"; classtype:trojan-activity; sid:100000560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.210.89.79"; classtype:trojan-activity; sid:100000561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.43.33.202"; classtype:trojan-activity; sid:100000562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.5.15.95"; classtype:trojan-activity; sid:100000563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.66.60"; classtype:trojan-activity; sid:100000564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.93.115"; classtype:trojan-activity; sid:100000565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.141.142"; classtype:trojan-activity; sid:100000566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.8.11"; classtype:trojan-activity; sid:100000567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.7.75.99"; classtype:trojan-activity; sid:100000568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.173.168"; classtype:trojan-activity; sid:100000569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.174.3"; classtype:trojan-activity; sid:100000570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.210.232"; classtype:trojan-activity; sid:100000571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.114.164"; classtype:trojan-activity; sid:100000572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.96.8"; classtype:trojan-activity; sid:100000573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.121.44.222"; classtype:trojan-activity; sid:100000574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.122.71.122"; classtype:trojan-activity; sid:100000575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.123.53.25"; classtype:trojan-activity; sid:100000576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.127.155.220"; classtype:trojan-activity; sid:100000577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.141.11.56"; classtype:trojan-activity; sid:100000578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.15.142.137"; classtype:trojan-activity; sid:100000579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.159.22.144"; classtype:trojan-activity; sid:100000580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.170.234.142"; classtype:trojan-activity; sid:100000581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.185.31.2"; classtype:trojan-activity; sid:100000582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.190.36.8"; classtype:trojan-activity; sid:100000583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.20.104.26"; classtype:trojan-activity; sid:100000584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.225.11.163"; classtype:trojan-activity; sid:100000585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.23.57.130"; classtype:trojan-activity; sid:100000586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.230.171.198"; classtype:trojan-activity; sid:100000587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.231.103.95"; classtype:trojan-activity; sid:100000588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.237.226.202"; classtype:trojan-activity; sid:100000589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.239.15.74"; classtype:trojan-activity; sid:100000590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.24.116.173"; classtype:trojan-activity; sid:100000591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.25.101.86"; classtype:trojan-activity; sid:100000592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.254.43.215"; classtype:trojan-activity; sid:100000593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.254.76.17"; classtype:trojan-activity; sid:100000594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.101.125"; classtype:trojan-activity; sid:100000595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.98.151"; classtype:trojan-activity; sid:100000596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.88.99.236"; classtype:trojan-activity; sid:100000597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.100.150.204"; classtype:trojan-activity; sid:100000598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.159.178.39"; classtype:trojan-activity; sid:100000599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.160.147.53"; classtype:trojan-activity; sid:100000600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.176.44.34"; classtype:trojan-activity; sid:100000601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.188.86.225"; classtype:trojan-activity; sid:100000602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.66.28"; classtype:trojan-activity; sid:100000603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.72.23"; classtype:trojan-activity; sid:100000604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.79.27"; classtype:trojan-activity; sid:100000605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.83.86"; classtype:trojan-activity; sid:100000606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.37.85"; classtype:trojan-activity; sid:100000607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.41.23"; classtype:trojan-activity; sid:100000608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.29.37"; classtype:trojan-activity; sid:100000609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.33.214"; classtype:trojan-activity; sid:100000610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.0.240.58"; classtype:trojan-activity; sid:100000611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.54.57"; classtype:trojan-activity; sid:100000612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.238"; classtype:trojan-activity; sid:100000613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.244"; classtype:trojan-activity; sid:100000614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.170.237"; classtype:trojan-activity; sid:100000615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.182.187"; classtype:trojan-activity; sid:100000616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.19.248"; classtype:trojan-activity; sid:100000617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.200.98"; classtype:trojan-activity; sid:100000618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.238.188"; classtype:trojan-activity; sid:100000619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.128.133.91"; classtype:trojan-activity; sid:100000620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.129.84.36"; classtype:trojan-activity; sid:100000621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.208.52"; classtype:trojan-activity; sid:100000622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.23.110"; classtype:trojan-activity; sid:100000623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.27.19"; classtype:trojan-activity; sid:100000624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.37.182"; classtype:trojan-activity; sid:100000625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.61.210"; classtype:trojan-activity; sid:100000626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.77.225"; classtype:trojan-activity; sid:100000627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.131.186.250"; classtype:trojan-activity; sid:100000628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.132.219.147"; classtype:trojan-activity; sid:100000629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.125.77"; classtype:trojan-activity; sid:100000630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.98.135"; classtype:trojan-activity; sid:100000631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.134.14.130"; classtype:trojan-activity; sid:100000632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.134.50.186"; classtype:trojan-activity; sid:100000633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.120.130"; classtype:trojan-activity; sid:100000634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.199.130"; classtype:trojan-activity; sid:100000635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.153.80.178"; classtype:trojan-activity; sid:100000636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.116.116"; classtype:trojan-activity; sid:100000637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.236.114"; classtype:trojan-activity; sid:100000638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.94.1"; classtype:trojan-activity; sid:100000639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.156.136.21"; classtype:trojan-activity; sid:100000640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.8.100"; classtype:trojan-activity; sid:100000641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.183.121.60"; classtype:trojan-activity; sid:100000642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.191.150.147"; classtype:trojan-activity; sid:100000643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.191.164.92"; classtype:trojan-activity; sid:100000644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.101.163"; classtype:trojan-activity; sid:100000645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.194.233"; classtype:trojan-activity; sid:100000646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.149.235"; classtype:trojan-activity; sid:100000647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.53.237"; classtype:trojan-activity; sid:100000648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.235.37"; classtype:trojan-activity; sid:100000649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.35.146"; classtype:trojan-activity; sid:100000650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.52.79"; classtype:trojan-activity; sid:100000651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.60.238"; classtype:trojan-activity; sid:100000652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.112.240"; classtype:trojan-activity; sid:100000653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.184.191"; classtype:trojan-activity; sid:100000654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.98.141"; classtype:trojan-activity; sid:100000655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.212.29.154"; classtype:trojan-activity; sid:100000656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.213.225.130"; classtype:trojan-activity; sid:100000657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.130.162"; classtype:trojan-activity; sid:100000658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.152.249"; classtype:trojan-activity; sid:100000659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.116.110"; classtype:trojan-activity; sid:100000660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.184.57"; classtype:trojan-activity; sid:100000661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.235.226.3"; classtype:trojan-activity; sid:100000662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.103.89"; classtype:trojan-activity; sid:100000663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.181.57"; classtype:trojan-activity; sid:100000664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.79.61"; classtype:trojan-activity; sid:100000665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.148.58"; classtype:trojan-activity; sid:100000666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.184.124"; classtype:trojan-activity; sid:100000667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.28.217.23"; classtype:trojan-activity; sid:100000668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.189.116"; classtype:trojan-activity; sid:100000669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.5.242"; classtype:trojan-activity; sid:100000670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.184.82"; classtype:trojan-activity; sid:100000671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.119.108.87"; classtype:trojan-activity; sid:100000672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.221.150"; classtype:trojan-activity; sid:100000673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.76.230"; classtype:trojan-activity; sid:100000674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.130.110.167"; classtype:trojan-activity; sid:100000675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.130.40.31"; classtype:trojan-activity; sid:100000676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.104.82"; classtype:trojan-activity; sid:100000677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.151.135"; classtype:trojan-activity; sid:100000678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.203.190"; classtype:trojan-activity; sid:100000679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.24.185"; classtype:trojan-activity; sid:100000680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.26.243"; classtype:trojan-activity; sid:100000681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.54.33"; classtype:trojan-activity; sid:100000682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.132.110.150"; classtype:trojan-activity; sid:100000683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.135.34.49"; classtype:trojan-activity; sid:100000684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.136.175"; classtype:trojan-activity; sid:100000685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.236.6"; classtype:trojan-activity; sid:100000686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.160.126.238"; classtype:trojan-activity; sid:100000687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.163.193"; classtype:trojan-activity; sid:100000688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.65.64"; classtype:trojan-activity; sid:100000689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.72.102"; classtype:trojan-activity; sid:100000690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.165.123.7"; classtype:trojan-activity; sid:100000691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.187.111.160"; classtype:trojan-activity; sid:100000692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.199.56.198"; classtype:trojan-activity; sid:100000693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.230.174.233"; classtype:trojan-activity; sid:100000694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.254.251.54"; classtype:trojan-activity; sid:100000695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.5.92.20"; classtype:trojan-activity; sid:100000696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.6.0.4"; classtype:trojan-activity; sid:100000697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.67.89.28"; classtype:trojan-activity; sid:100000698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.7.254.85"; classtype:trojan-activity; sid:100000699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.80.46.73"; classtype:trojan-activity; sid:100000700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.91.135.234"; classtype:trojan-activity; sid:100000701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.91.237.147"; classtype:trojan-activity; sid:100000702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.93.94.207"; classtype:trojan-activity; sid:100000703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.128.28.161"; classtype:trojan-activity; sid:100000704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.142.93.34"; classtype:trojan-activity; sid:100000705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.191.113.212"; classtype:trojan-activity; sid:100000706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.1.235"; classtype:trojan-activity; sid:100000707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.73.6"; classtype:trojan-activity; sid:100000708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.75.22"; classtype:trojan-activity; sid:100000709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.215.9"; classtype:trojan-activity; sid:100000710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.53.9"; classtype:trojan-activity; sid:100000711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.63.67"; classtype:trojan-activity; sid:100000712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.129.159"; classtype:trojan-activity; sid:100000713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.79.200.104"; classtype:trojan-activity; sid:100000714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"128.116.133.92"; classtype:trojan-activity; sid:100000715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"130.255.159.133"; classtype:trojan-activity; sid:100000716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"134.195.139.4"; classtype:trojan-activity; sid:100000717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"135.148.36.127"; classtype:trojan-activity; sid:100000718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"138.99.204.224"; classtype:trojan-activity; sid:100000719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.159.226.180"; classtype:trojan-activity; sid:100000720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.170.173.198"; classtype:trojan-activity; sid:100000721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.216.102.151"; classtype:trojan-activity; sid:100000722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.227.46.137"; classtype:trojan-activity; sid:100000723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.102.17.222"; classtype:trojan-activity; sid:100000724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.136.80.242"; classtype:trojan-activity; sid:100000725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.51"; classtype:trojan-activity; sid:100000726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.178.163.235"; classtype:trojan-activity; sid:100000727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.189.247.118"; classtype:trojan-activity; sid:100000728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.37.222.190"; classtype:trojan-activity; sid:100000729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.45.127.110"; classtype:trojan-activity; sid:100000730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.25.17"; classtype:trojan-activity; sid:100000731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.98.241"; classtype:trojan-activity; sid:100000732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.55.29.2"; classtype:trojan-activity; sid:100000733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"141.105.65.94"; classtype:trojan-activity; sid:100000734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.11.216.5"; classtype:trojan-activity; sid:100000735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.177.56.127"; classtype:trojan-activity; sid:100000736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"146.71.79.230"; classtype:trojan-activity; sid:100000737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"148.69.108.177"; classtype:trojan-activity; sid:100000738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.20.176.179"; classtype:trojan-activity; sid:100000739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.134"; classtype:trojan-activity; sid:100000740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.172"; classtype:trojan-activity; sid:100000741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.184"; classtype:trojan-activity; sid:100000742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.38"; classtype:trojan-activity; sid:100000743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.99"; classtype:trojan-activity; sid:100000744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.3.124.223"; classtype:trojan-activity; sid:100000745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.3.85.55"; classtype:trojan-activity; sid:100000746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14karatvisions.com"; classtype:trojan-activity; sid:100000747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"150.116.207.99"; classtype:trojan-activity; sid:100000748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.177.163.87"; classtype:trojan-activity; sid:100000749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.33.230.191"; classtype:trojan-activity; sid:100000750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.234.167"; classtype:trojan-activity; sid:100000751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.47.145"; classtype:trojan-activity; sid:100000752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.152.106"; classtype:trojan-activity; sid:100000753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.135.92"; classtype:trojan-activity; sid:100000754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.36.126.35"; classtype:trojan-activity; sid:100000755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"155.138.134.44"; classtype:trojan-activity; sid:100000756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.101.165.14"; classtype:trojan-activity; sid:100000757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.174.213.128"; classtype:trojan-activity; sid:100000758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.247.195.165"; classtype:trojan-activity; sid:100000759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.51.125.115"; classtype:trojan-activity; sid:100000760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"159.224.74.112"; classtype:trojan-activity; sid:100000761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.194.28.60"; classtype:trojan-activity; sid:100000762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.209.98.174"; classtype:trojan-activity; sid:100000763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.53.206.228"; classtype:trojan-activity; sid:100000764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"165.90.16.5"; classtype:trojan-activity; sid:100000765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"168.205.223.254"; classtype:trojan-activity; sid:100000766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"170.81.238.178"; classtype:trojan-activity; sid:100000767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.113.36.216"; classtype:trojan-activity; sid:100000768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.113.38.107"; classtype:trojan-activity; sid:100000769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.121.255.10"; classtype:trojan-activity; sid:100000770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.112.42"; classtype:trojan-activity; sid:100000771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.114.181"; classtype:trojan-activity; sid:100000772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.176.217"; classtype:trojan-activity; sid:100000773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.179.178"; classtype:trojan-activity; sid:100000774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.162.156"; classtype:trojan-activity; sid:100000775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.174.198"; classtype:trojan-activity; sid:100000776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.105.36.168"; classtype:trojan-activity; sid:100000777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.114.244.127"; classtype:trojan-activity; sid:100000778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.185"; classtype:trojan-activity; sid:100000779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.190"; classtype:trojan-activity; sid:100000780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.81.19"; classtype:trojan-activity; sid:100000781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.93.194.114"; classtype:trojan-activity; sid:100000782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.167.85.89"; classtype:trojan-activity; sid:100000783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.169.46.85"; classtype:trojan-activity; sid:100000784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.19.58.108"; classtype:trojan-activity; sid:100000785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.233.85.171"; classtype:trojan-activity; sid:100000786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.235.209.70"; classtype:trojan-activity; sid:100000787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.25.113.8"; classtype:trojan-activity; sid:100000788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.95.134"; classtype:trojan-activity; sid:100000789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.97.25"; classtype:trojan-activity; sid:100000790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.119.108"; classtype:trojan-activity; sid:100000791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.92.166"; classtype:trojan-activity; sid:100000792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.106.33.85"; classtype:trojan-activity; sid:100000793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.48.181.23"; classtype:trojan-activity; sid:100000794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.61.3.149"; classtype:trojan-activity; sid:100000795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.73.246.193"; classtype:trojan-activity; sid:100000796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.81.78.7"; classtype:trojan-activity; sid:100000797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.83.73.163"; classtype:trojan-activity; sid:100000798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.10.147.167"; classtype:trojan-activity; sid:100000799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.11.193.66"; classtype:trojan-activity; sid:100000800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.11.65.112"; classtype:trojan-activity; sid:100000801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.117.66.74"; classtype:trojan-activity; sid:100000802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.145.200.216"; classtype:trojan-activity; sid:100000803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.169.13.182"; classtype:trojan-activity; sid:100000804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.201.104.192"; classtype:trojan-activity; sid:100000805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.208.230.8"; classtype:trojan-activity; sid:100000806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.212.6.169"; classtype:trojan-activity; sid:100000807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.42.46.118"; classtype:trojan-activity; sid:100000808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.9.24.110"; classtype:trojan-activity; sid:100000809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.9.90.89"; classtype:trojan-activity; sid:100000810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.14"; classtype:trojan-activity; sid:100000811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.249"; classtype:trojan-activity; sid:100000812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.35"; classtype:trojan-activity; sid:100000813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.63"; classtype:trojan-activity; sid:100000814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.66"; classtype:trojan-activity; sid:100000815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.67"; classtype:trojan-activity; sid:100000816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.104"; classtype:trojan-activity; sid:100000817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.113"; classtype:trojan-activity; sid:100000818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.138"; classtype:trojan-activity; sid:100000819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.60"; classtype:trojan-activity; sid:100000820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.65"; classtype:trojan-activity; sid:100000821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.66"; classtype:trojan-activity; sid:100000822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.68"; classtype:trojan-activity; sid:100000823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.84"; classtype:trojan-activity; sid:100000824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.91"; classtype:trojan-activity; sid:100000825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.93"; classtype:trojan-activity; sid:100000826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.12.117.70"; classtype:trojan-activity; sid:100000827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.4.115"; classtype:trojan-activity; sid:100000828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.115"; classtype:trojan-activity; sid:100000829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.127"; classtype:trojan-activity; sid:100000830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.9.243"; classtype:trojan-activity; sid:100000831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.124.7.225"; classtype:trojan-activity; sid:100000832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.221.242.166"; classtype:trojan-activity; sid:100000833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.240.84.106"; classtype:trojan-activity; sid:100000834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.11.92.78"; classtype:trojan-activity; sid:100000835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.131.226.235"; classtype:trojan-activity; sid:100000836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.229.64.218"; classtype:trojan-activity; sid:100000837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.54.82.154"; classtype:trojan-activity; sid:100000838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.86.99.5"; classtype:trojan-activity; sid:100000839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.124.182.187"; classtype:trojan-activity; sid:100000840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.142.15"; classtype:trojan-activity; sid:100000841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.150.174.65"; classtype:trojan-activity; sid:100000842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.165.122.141"; classtype:trojan-activity; sid:100000843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.0.200"; classtype:trojan-activity; sid:100000844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.137"; classtype:trojan-activity; sid:100000845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.153"; classtype:trojan-activity; sid:100000846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.179"; classtype:trojan-activity; sid:100000847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.248"; classtype:trojan-activity; sid:100000848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.249"; classtype:trojan-activity; sid:100000849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.250"; classtype:trojan-activity; sid:100000850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.44"; classtype:trojan-activity; sid:100000851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.80"; classtype:trojan-activity; sid:100000852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.110"; classtype:trojan-activity; sid:100000853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.232"; classtype:trojan-activity; sid:100000854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.133"; classtype:trojan-activity; sid:100000855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.171"; classtype:trojan-activity; sid:100000856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.67"; classtype:trojan-activity; sid:100000857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.98"; classtype:trojan-activity; sid:100000858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.145"; classtype:trojan-activity; sid:100000859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.155"; classtype:trojan-activity; sid:100000860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.69"; classtype:trojan-activity; sid:100000861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.125"; classtype:trojan-activity; sid:100000862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.95"; classtype:trojan-activity; sid:100000863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.118"; classtype:trojan-activity; sid:100000864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.193"; classtype:trojan-activity; sid:100000865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.201"; classtype:trojan-activity; sid:100000866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.0"; classtype:trojan-activity; sid:100000867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.245"; classtype:trojan-activity; sid:100000868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.83"; classtype:trojan-activity; sid:100000869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.105"; classtype:trojan-activity; sid:100000870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.149"; classtype:trojan-activity; sid:100000871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.87"; classtype:trojan-activity; sid:100000872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.129"; classtype:trojan-activity; sid:100000873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.26"; classtype:trojan-activity; sid:100000874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.126"; classtype:trojan-activity; sid:100000875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.239"; classtype:trojan-activity; sid:100000876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.252"; classtype:trojan-activity; sid:100000877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.190"; classtype:trojan-activity; sid:100000878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.195"; classtype:trojan-activity; sid:100000879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.206"; classtype:trojan-activity; sid:100000880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.135"; classtype:trojan-activity; sid:100000881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.139"; classtype:trojan-activity; sid:100000882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.147"; classtype:trojan-activity; sid:100000883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.159"; classtype:trojan-activity; sid:100000884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.46"; classtype:trojan-activity; sid:100000885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.58"; classtype:trojan-activity; sid:100000886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.27"; classtype:trojan-activity; sid:100000887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.114"; classtype:trojan-activity; sid:100000888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.63"; classtype:trojan-activity; sid:100000889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.110"; classtype:trojan-activity; sid:100000890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.209"; classtype:trojan-activity; sid:100000891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.101"; classtype:trojan-activity; sid:100000892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.138"; classtype:trojan-activity; sid:100000893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.168"; classtype:trojan-activity; sid:100000894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.90"; classtype:trojan-activity; sid:100000895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.30"; classtype:trojan-activity; sid:100000896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.112"; classtype:trojan-activity; sid:100000897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.146"; classtype:trojan-activity; sid:100000898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.210"; classtype:trojan-activity; sid:100000899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.102"; classtype:trojan-activity; sid:100000900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.114"; classtype:trojan-activity; sid:100000901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.69"; classtype:trojan-activity; sid:100000902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.70"; classtype:trojan-activity; sid:100000903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.93"; classtype:trojan-activity; sid:100000904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.123"; classtype:trojan-activity; sid:100000905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.151"; classtype:trojan-activity; sid:100000906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.199"; classtype:trojan-activity; sid:100000907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.228"; classtype:trojan-activity; sid:100000908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.28"; classtype:trojan-activity; sid:100000909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.74"; classtype:trojan-activity; sid:100000910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.9"; classtype:trojan-activity; sid:100000911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.1"; classtype:trojan-activity; sid:100000912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.168"; classtype:trojan-activity; sid:100000913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.191"; classtype:trojan-activity; sid:100000914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.2"; classtype:trojan-activity; sid:100000915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.202"; classtype:trojan-activity; sid:100000916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.248"; classtype:trojan-activity; sid:100000917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.26"; classtype:trojan-activity; sid:100000918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.30"; classtype:trojan-activity; sid:100000919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.48"; classtype:trojan-activity; sid:100000920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.91"; classtype:trojan-activity; sid:100000921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.131"; classtype:trojan-activity; sid:100000922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.155"; classtype:trojan-activity; sid:100000923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.4"; classtype:trojan-activity; sid:100000924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.79"; classtype:trojan-activity; sid:100000925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.14"; classtype:trojan-activity; sid:100000926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.160"; classtype:trojan-activity; sid:100000927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.220"; classtype:trojan-activity; sid:100000928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.88"; classtype:trojan-activity; sid:100000929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.129"; classtype:trojan-activity; sid:100000930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.153"; classtype:trojan-activity; sid:100000931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.252"; classtype:trojan-activity; sid:100000932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.46"; classtype:trojan-activity; sid:100000933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.202"; classtype:trojan-activity; sid:100000934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.231"; classtype:trojan-activity; sid:100000935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.43"; classtype:trojan-activity; sid:100000936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.222"; classtype:trojan-activity; sid:100000937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.254"; classtype:trojan-activity; sid:100000938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.199"; classtype:trojan-activity; sid:100000939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.215"; classtype:trojan-activity; sid:100000940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.35"; classtype:trojan-activity; sid:100000941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.108"; classtype:trojan-activity; sid:100000942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.116"; classtype:trojan-activity; sid:100000943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.251"; classtype:trojan-activity; sid:100000944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.7"; classtype:trojan-activity; sid:100000945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.73"; classtype:trojan-activity; sid:100000946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.118"; classtype:trojan-activity; sid:100000947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.61"; classtype:trojan-activity; sid:100000948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.23"; classtype:trojan-activity; sid:100000949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.75"; classtype:trojan-activity; sid:100000950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.163"; classtype:trojan-activity; sid:100000951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.174"; classtype:trojan-activity; sid:100000952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.91"; classtype:trojan-activity; sid:100000953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.118"; classtype:trojan-activity; sid:100000954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.123"; classtype:trojan-activity; sid:100000955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.209"; classtype:trojan-activity; sid:100000956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.5"; classtype:trojan-activity; sid:100000957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.117"; classtype:trojan-activity; sid:100000958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.70"; classtype:trojan-activity; sid:100000959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.97"; classtype:trojan-activity; sid:100000960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.149"; classtype:trojan-activity; sid:100000961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.184"; classtype:trojan-activity; sid:100000962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.238"; classtype:trojan-activity; sid:100000963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.237"; classtype:trojan-activity; sid:100000964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.144"; classtype:trojan-activity; sid:100000965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.176"; classtype:trojan-activity; sid:100000966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.146"; classtype:trojan-activity; sid:100000967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.172"; classtype:trojan-activity; sid:100000968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.117"; classtype:trojan-activity; sid:100000969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.152"; classtype:trojan-activity; sid:100000970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.177"; classtype:trojan-activity; sid:100000971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.56"; classtype:trojan-activity; sid:100000972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.215"; classtype:trojan-activity; sid:100000973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.114"; classtype:trojan-activity; sid:100000974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.127"; classtype:trojan-activity; sid:100000975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.171"; classtype:trojan-activity; sid:100000976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.213"; classtype:trojan-activity; sid:100000977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.32"; classtype:trojan-activity; sid:100000978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.37"; classtype:trojan-activity; sid:100000979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.46"; classtype:trojan-activity; sid:100000980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.239"; classtype:trojan-activity; sid:100000981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.47"; classtype:trojan-activity; sid:100000982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.2"; classtype:trojan-activity; sid:100000983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.21"; classtype:trojan-activity; sid:100000984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.172"; classtype:trojan-activity; sid:100000985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.214"; classtype:trojan-activity; sid:100000986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.133"; classtype:trojan-activity; sid:100000987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.151"; classtype:trojan-activity; sid:100000988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.213"; classtype:trojan-activity; sid:100000989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.251"; classtype:trojan-activity; sid:100000990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.73"; classtype:trojan-activity; sid:100000991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.146"; classtype:trojan-activity; sid:100000992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.220"; classtype:trojan-activity; sid:100000993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.89"; classtype:trojan-activity; sid:100000994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.7"; classtype:trojan-activity; sid:100000995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.217"; classtype:trojan-activity; sid:100000996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.247"; classtype:trojan-activity; sid:100000997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.253"; classtype:trojan-activity; sid:100000998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.36"; classtype:trojan-activity; sid:100000999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.83"; classtype:trojan-activity; sid:100001000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.126"; classtype:trojan-activity; sid:100001001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.218"; classtype:trojan-activity; sid:100001002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.57"; classtype:trojan-activity; sid:100001003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.6"; classtype:trojan-activity; sid:100001004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.103"; classtype:trojan-activity; sid:100001005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.132"; classtype:trojan-activity; sid:100001006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.200"; classtype:trojan-activity; sid:100001007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.144"; classtype:trojan-activity; sid:100001008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.72"; classtype:trojan-activity; sid:100001009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.136"; classtype:trojan-activity; sid:100001010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.166"; classtype:trojan-activity; sid:100001011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.228"; classtype:trojan-activity; sid:100001012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.101"; classtype:trojan-activity; sid:100001013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.6"; classtype:trojan-activity; sid:100001014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.121"; classtype:trojan-activity; sid:100001015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.238"; classtype:trojan-activity; sid:100001016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.244"; classtype:trojan-activity; sid:100001017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.0"; classtype:trojan-activity; sid:100001018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.217"; classtype:trojan-activity; sid:100001019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.70"; classtype:trojan-activity; sid:100001020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.90"; classtype:trojan-activity; sid:100001021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.201"; classtype:trojan-activity; sid:100001022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.205"; classtype:trojan-activity; sid:100001023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.214"; classtype:trojan-activity; sid:100001024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.26"; classtype:trojan-activity; sid:100001025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.129"; classtype:trojan-activity; sid:100001026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.137"; classtype:trojan-activity; sid:100001027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.243"; classtype:trojan-activity; sid:100001028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.41"; classtype:trojan-activity; sid:100001029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.42"; classtype:trojan-activity; sid:100001030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.8"; classtype:trojan-activity; sid:100001031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.143"; classtype:trojan-activity; sid:100001032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.51"; classtype:trojan-activity; sid:100001033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.12"; classtype:trojan-activity; sid:100001034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.57"; classtype:trojan-activity; sid:100001035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.10"; classtype:trojan-activity; sid:100001036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.177"; classtype:trojan-activity; sid:100001037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.236"; classtype:trojan-activity; sid:100001038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.56"; classtype:trojan-activity; sid:100001039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.180"; classtype:trojan-activity; sid:100001040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.212"; classtype:trojan-activity; sid:100001041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.216"; classtype:trojan-activity; sid:100001042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.151"; classtype:trojan-activity; sid:100001043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.254"; classtype:trojan-activity; sid:100001044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.5"; classtype:trojan-activity; sid:100001045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.58"; classtype:trojan-activity; sid:100001046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.14"; classtype:trojan-activity; sid:100001047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.211"; classtype:trojan-activity; sid:100001048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.11"; classtype:trojan-activity; sid:100001049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.82"; classtype:trojan-activity; sid:100001050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.87"; classtype:trojan-activity; sid:100001051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.134"; classtype:trojan-activity; sid:100001052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.179"; classtype:trojan-activity; sid:100001053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.183"; classtype:trojan-activity; sid:100001054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.79"; classtype:trojan-activity; sid:100001055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.131"; classtype:trojan-activity; sid:100001056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.33"; classtype:trojan-activity; sid:100001057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.115"; classtype:trojan-activity; sid:100001058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.140"; classtype:trojan-activity; sid:100001059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.141"; classtype:trojan-activity; sid:100001060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.157"; classtype:trojan-activity; sid:100001061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.182"; classtype:trojan-activity; sid:100001062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.195"; classtype:trojan-activity; sid:100001063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.134"; classtype:trojan-activity; sid:100001064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.209"; classtype:trojan-activity; sid:100001065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.212"; classtype:trojan-activity; sid:100001066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.221"; classtype:trojan-activity; sid:100001067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.235"; classtype:trojan-activity; sid:100001068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.232"; classtype:trojan-activity; sid:100001069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.70"; classtype:trojan-activity; sid:100001070; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.81"; classtype:trojan-activity; sid:100001071; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.21"; classtype:trojan-activity; sid:100001072; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.156"; classtype:trojan-activity; sid:100001073; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.186"; classtype:trojan-activity; sid:100001074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.192"; classtype:trojan-activity; sid:100001075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.211"; classtype:trojan-activity; sid:100001076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.116"; classtype:trojan-activity; sid:100001077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.123"; classtype:trojan-activity; sid:100001078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.209"; classtype:trojan-activity; sid:100001079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.44"; classtype:trojan-activity; sid:100001080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.128"; classtype:trojan-activity; sid:100001081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.153"; classtype:trojan-activity; sid:100001082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.67"; classtype:trojan-activity; sid:100001083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.105"; classtype:trojan-activity; sid:100001084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.107"; classtype:trojan-activity; sid:100001085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.14"; classtype:trojan-activity; sid:100001086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.21"; classtype:trojan-activity; sid:100001087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.35"; classtype:trojan-activity; sid:100001088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.60"; classtype:trojan-activity; sid:100001089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.79"; classtype:trojan-activity; sid:100001090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.212"; classtype:trojan-activity; sid:100001091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.218"; classtype:trojan-activity; sid:100001092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.222"; classtype:trojan-activity; sid:100001093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.65"; classtype:trojan-activity; sid:100001094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.73.42"; classtype:trojan-activity; sid:100001095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.181"; classtype:trojan-activity; sid:100001096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.244"; classtype:trojan-activity; sid:100001097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.248"; classtype:trojan-activity; sid:100001098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.46"; classtype:trojan-activity; sid:100001099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.47"; classtype:trojan-activity; sid:100001100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.169"; classtype:trojan-activity; sid:100001101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.2"; classtype:trojan-activity; sid:100001102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.181"; classtype:trojan-activity; sid:100001103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.89"; classtype:trojan-activity; sid:100001104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.176"; classtype:trojan-activity; sid:100001105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.226"; classtype:trojan-activity; sid:100001106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.235"; classtype:trojan-activity; sid:100001107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.31"; classtype:trojan-activity; sid:100001108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.2"; classtype:trojan-activity; sid:100001109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.215"; classtype:trojan-activity; sid:100001110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.61"; classtype:trojan-activity; sid:100001111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.23"; classtype:trojan-activity; sid:100001112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.53"; classtype:trojan-activity; sid:100001113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.59"; classtype:trojan-activity; sid:100001114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.146"; classtype:trojan-activity; sid:100001115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.42"; classtype:trojan-activity; sid:100001116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.91"; classtype:trojan-activity; sid:100001117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.166"; classtype:trojan-activity; sid:100001118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.4"; classtype:trojan-activity; sid:100001119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.217"; classtype:trojan-activity; sid:100001120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.6"; classtype:trojan-activity; sid:100001121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.179"; classtype:trojan-activity; sid:100001122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.198"; classtype:trojan-activity; sid:100001123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.4"; classtype:trojan-activity; sid:100001124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.81"; classtype:trojan-activity; sid:100001125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.1"; classtype:trojan-activity; sid:100001126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.102"; classtype:trojan-activity; sid:100001127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.92"; classtype:trojan-activity; sid:100001128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.143"; classtype:trojan-activity; sid:100001129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.182"; classtype:trojan-activity; sid:100001130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.27"; classtype:trojan-activity; sid:100001131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.32"; classtype:trojan-activity; sid:100001132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.40"; classtype:trojan-activity; sid:100001133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.61"; classtype:trojan-activity; sid:100001134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.120"; classtype:trojan-activity; sid:100001135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.218"; classtype:trojan-activity; sid:100001136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.251"; classtype:trojan-activity; sid:100001137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.14"; classtype:trojan-activity; sid:100001138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.83"; classtype:trojan-activity; sid:100001139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.120"; classtype:trojan-activity; sid:100001140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.130"; classtype:trojan-activity; sid:100001141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.77"; classtype:trojan-activity; sid:100001142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.19.183.14"; classtype:trojan-activity; sid:100001143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.205.101.33"; classtype:trojan-activity; sid:100001144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.21.164.68"; classtype:trojan-activity; sid:100001145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.217.8.194"; classtype:trojan-activity; sid:100001146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.22.117.102"; classtype:trojan-activity; sid:100001147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.222.252.130"; classtype:trojan-activity; sid:100001148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.34.183.30"; classtype:trojan-activity; sid:100001149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.48.235.59"; classtype:trojan-activity; sid:100001150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.72.91.172"; classtype:trojan-activity; sid:100001151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.95.136.35"; classtype:trojan-activity; sid:100001152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.159.58.134"; classtype:trojan-activity; sid:100001153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.60.84.7"; classtype:trojan-activity; sid:100001154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.99.210.161"; classtype:trojan-activity; sid:100001155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.114.60.229"; classtype:trojan-activity; sid:100001156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.116.203.220"; classtype:trojan-activity; sid:100001157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.122.13.227"; classtype:trojan-activity; sid:100001158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.123.208.250"; classtype:trojan-activity; sid:100001159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.125.44.194"; classtype:trojan-activity; sid:100001160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.157.66.204"; classtype:trojan-activity; sid:100001161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.175.236.209"; classtype:trojan-activity; sid:100001162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.105.41"; classtype:trojan-activity; sid:100001163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.110.243"; classtype:trojan-activity; sid:100001164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.165.230"; classtype:trojan-activity; sid:100001165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.214.171"; classtype:trojan-activity; sid:100001166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.34.51"; classtype:trojan-activity; sid:100001167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.96.248"; classtype:trojan-activity; sid:100001168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.104.65"; classtype:trojan-activity; sid:100001169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.180.6"; classtype:trojan-activity; sid:100001170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.242.73"; classtype:trojan-activity; sid:100001171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.218.5.171"; classtype:trojan-activity; sid:100001172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.248.80.38"; classtype:trojan-activity; sid:100001173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.111.36"; classtype:trojan-activity; sid:100001174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.53.93"; classtype:trojan-activity; sid:100001175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.94.170.166"; classtype:trojan-activity; sid:100001176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.138.154"; classtype:trojan-activity; sid:100001177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.218.238"; classtype:trojan-activity; sid:100001178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.218.6"; classtype:trojan-activity; sid:100001179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.143.60.163"; classtype:trojan-activity; sid:100001180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.193.107.10"; classtype:trojan-activity; sid:100001181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.222"; classtype:trojan-activity; sid:100001182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.230"; classtype:trojan-activity; sid:100001183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.210.45.42"; classtype:trojan-activity; sid:100001184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.215.47.82"; classtype:trojan-activity; sid:100001185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.224.242.131"; classtype:trojan-activity; sid:100001186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.236.4"; classtype:trojan-activity; sid:100001187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.59.162"; classtype:trojan-activity; sid:100001188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.113.209.187"; classtype:trojan-activity; sid:100001189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.108.244"; classtype:trojan-activity; sid:100001190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.43.47"; classtype:trojan-activity; sid:100001191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.60.73"; classtype:trojan-activity; sid:100001192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.61.252"; classtype:trojan-activity; sid:100001193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.99.150"; classtype:trojan-activity; sid:100001194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.43.185"; classtype:trojan-activity; sid:100001195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.43.82"; classtype:trojan-activity; sid:100001196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.120.8"; classtype:trojan-activity; sid:100001197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.164.128"; classtype:trojan-activity; sid:100001198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.200.62"; classtype:trojan-activity; sid:100001199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.202.130"; classtype:trojan-activity; sid:100001200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.22"; classtype:trojan-activity; sid:100001201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.46"; classtype:trojan-activity; sid:100001202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.127.106"; classtype:trojan-activity; sid:100001203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.123.205.157"; classtype:trojan-activity; sid:100001204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.123.211.239"; classtype:trojan-activity; sid:100001205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.138.54"; classtype:trojan-activity; sid:100001206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.121.211"; classtype:trojan-activity; sid:100001207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.152.3"; classtype:trojan-activity; sid:100001208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.160.98.250"; classtype:trojan-activity; sid:100001209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.233.0.252"; classtype:trojan-activity; sid:100001210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.235.252.31"; classtype:trojan-activity; sid:100001211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.53.197.62"; classtype:trojan-activity; sid:100001212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.105.104.83"; classtype:trojan-activity; sid:100001213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.105.225.154"; classtype:trojan-activity; sid:100001214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.109.169.45"; classtype:trojan-activity; sid:100001215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.128.152.115"; classtype:trojan-activity; sid:100001216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.144.9.97"; classtype:trojan-activity; sid:100001217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.185.112.19"; classtype:trojan-activity; sid:100001218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.18.203"; classtype:trojan-activity; sid:100001219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.29.191"; classtype:trojan-activity; sid:100001220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.92.207.147"; classtype:trojan-activity; sid:100001221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.164.185.41"; classtype:trojan-activity; sid:100001222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.175.115.10"; classtype:trojan-activity; sid:100001223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.74.149.230"; classtype:trojan-activity; sid:100001224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.106.209.68"; classtype:trojan-activity; sid:100001225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.107.3.8"; classtype:trojan-activity; sid:100001226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.117.2.107"; classtype:trojan-activity; sid:100001227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.172.110.235"; classtype:trojan-activity; sid:100001228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.174.101.41"; classtype:trojan-activity; sid:100001229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.181.10.234"; classtype:trojan-activity; sid:100001230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.112"; classtype:trojan-activity; sid:100001231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.54"; classtype:trojan-activity; sid:100001232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.77"; classtype:trojan-activity; sid:100001233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.93"; classtype:trojan-activity; sid:100001234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.221.3.244"; classtype:trojan-activity; sid:100001235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.222.58.152"; classtype:trojan-activity; sid:100001236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.228.141.74"; classtype:trojan-activity; sid:100001237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.233.186.151"; classtype:trojan-activity; sid:100001238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.26.113.95"; classtype:trojan-activity; sid:100001239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.34.16.231"; classtype:trojan-activity; sid:100001240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.43.19.151"; classtype:trojan-activity; sid:100001241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.55.1.182"; classtype:trojan-activity; sid:100001242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.68.230.207"; classtype:trojan-activity; sid:100001243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.81.157.186"; classtype:trojan-activity; sid:100001244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.185"; classtype:trojan-activity; sid:100001245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.213"; classtype:trojan-activity; sid:100001246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.160"; classtype:trojan-activity; sid:100001247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.161"; classtype:trojan-activity; sid:100001248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.219"; classtype:trojan-activity; sid:100001249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.80"; classtype:trojan-activity; sid:100001250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.151.144.85"; classtype:trojan-activity; sid:100001251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.219.164"; classtype:trojan-activity; sid:100001252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.112"; classtype:trojan-activity; sid:100001253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.77"; classtype:trojan-activity; sid:100001254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.91"; classtype:trojan-activity; sid:100001255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.253.150"; classtype:trojan-activity; sid:100001256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.225.120.173"; classtype:trojan-activity; sid:100001257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.232.44.86"; classtype:trojan-activity; sid:100001258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.28.60.184"; classtype:trojan-activity; sid:100001259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.34.4.40"; classtype:trojan-activity; sid:100001260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.73.188.132"; classtype:trojan-activity; sid:100001261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.12.10.98"; classtype:trojan-activity; sid:100001262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.188.124.229"; classtype:trojan-activity; sid:100001263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.212.200.162"; classtype:trojan-activity; sid:100001264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.85.244.145"; classtype:trojan-activity; sid:100001265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.21.14"; classtype:trojan-activity; sid:100001266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.231.246"; classtype:trojan-activity; sid:100001267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.113.81.17"; classtype:trojan-activity; sid:100001268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.13.179.87"; classtype:trojan-activity; sid:100001269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.138.200.32"; classtype:trojan-activity; sid:100001270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.143.220.152"; classtype:trojan-activity; sid:100001271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.152.41.141"; classtype:trojan-activity; sid:100001272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.178.50"; classtype:trojan-activity; sid:100001273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.242.242.144"; classtype:trojan-activity; sid:100001274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.81.100.83"; classtype:trojan-activity; sid:100001275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.83.202.25"; classtype:trojan-activity; sid:100001276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"189.222.157.241"; classtype:trojan-activity; sid:100001277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.0.42.106"; classtype:trojan-activity; sid:100001278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.109.178.139"; classtype:trojan-activity; sid:100001279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.110.161.252"; classtype:trojan-activity; sid:100001280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.111.151.164"; classtype:trojan-activity; sid:100001281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.119.207.58"; classtype:trojan-activity; sid:100001282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.12.99.194"; classtype:trojan-activity; sid:100001283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.160"; classtype:trojan-activity; sid:100001284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.3"; classtype:trojan-activity; sid:100001285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.37"; classtype:trojan-activity; sid:100001286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.41"; classtype:trojan-activity; sid:100001287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.42"; classtype:trojan-activity; sid:100001288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.15.212"; classtype:trojan-activity; sid:100001289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.20.14"; classtype:trojan-activity; sid:100001290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.147.16.184"; classtype:trojan-activity; sid:100001291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.159.240.9"; classtype:trojan-activity; sid:100001292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.187.55.150"; classtype:trojan-activity; sid:100001293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.210.214.130"; classtype:trojan-activity; sid:100001294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.177.39"; classtype:trojan-activity; sid:100001295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.226.63"; classtype:trojan-activity; sid:100001296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.49.207"; classtype:trojan-activity; sid:100001297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.214.24.194"; classtype:trojan-activity; sid:100001298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.216.140.123"; classtype:trojan-activity; sid:100001299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.65.206.162"; classtype:trojan-activity; sid:100001300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.73.12.149"; classtype:trojan-activity; sid:100001301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.92.4.231"; classtype:trojan-activity; sid:100001302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.135"; classtype:trojan-activity; sid:100001303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.200"; classtype:trojan-activity; sid:100001304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.41.33"; classtype:trojan-activity; sid:100001305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"191.254.225.48"; classtype:trojan-activity; sid:100001306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"191.255.248.220"; classtype:trojan-activity; sid:100001307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.153.57.63"; classtype:trojan-activity; sid:100001308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.210.175.130"; classtype:trojan-activity; sid:100001309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.185.106"; classtype:trojan-activity; sid:100001310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.209.27"; classtype:trojan-activity; sid:100001311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.220.55"; classtype:trojan-activity; sid:100001312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.223.96"; classtype:trojan-activity; sid:100001313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.228.67"; classtype:trojan-activity; sid:100001314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.230.74"; classtype:trojan-activity; sid:100001315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.3.152.166"; classtype:trojan-activity; sid:100001316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.3.73.205"; classtype:trojan-activity; sid:100001317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.99.240.77"; classtype:trojan-activity; sid:100001318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.142.146.25"; classtype:trojan-activity; sid:100001319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.228.135.144"; classtype:trojan-activity; sid:100001320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.113.107.243"; classtype:trojan-activity; sid:100001321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.147.142.230"; classtype:trojan-activity; sid:100001322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.15.36.167"; classtype:trojan-activity; sid:100001323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.15.36.238"; classtype:trojan-activity; sid:100001324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.152.35.139"; classtype:trojan-activity; sid:100001325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.38.20.199"; classtype:trojan-activity; sid:100001326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.139.126.51"; classtype:trojan-activity; sid:100001327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.162.70.104"; classtype:trojan-activity; sid:100001328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.228.231.218"; classtype:trojan-activity; sid:100001329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.24.94.187"; classtype:trojan-activity; sid:100001330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.202.26.182"; classtype:trojan-activity; sid:100001331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.218.48.82"; classtype:trojan-activity; sid:100001332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.166.203"; classtype:trojan-activity; sid:100001333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.50.27.115"; classtype:trojan-activity; sid:100001334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.133.218"; classtype:trojan-activity; sid:100001335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.174.104"; classtype:trojan-activity; sid:100001336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.207.121"; classtype:trojan-activity; sid:100001337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.213.57"; classtype:trojan-activity; sid:100001338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.251.105"; classtype:trojan-activity; sid:100001339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.251.121"; classtype:trojan-activity; sid:100001340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.46.132.132"; classtype:trojan-activity; sid:100001341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.46.201.76"; classtype:trojan-activity; sid:100001342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"199.188.101.109"; classtype:trojan-activity; sid:100001343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1am.co.nz"; classtype:trojan-activity; sid:100001344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.229.89.119"; classtype:trojan-activity; sid:100001345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.239.22.188"; classtype:trojan-activity; sid:100001346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.249.161.188"; classtype:trojan-activity; sid:100001347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.37.149.230"; classtype:trojan-activity; sid:100001348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.37.203.65"; classtype:trojan-activity; sid:100001349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.4.24"; classtype:trojan-activity; sid:100001350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.125.182"; classtype:trojan-activity; sid:100001351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.92.184"; classtype:trojan-activity; sid:100001352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.57.122.107"; classtype:trojan-activity; sid:100001353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.83.152.16"; classtype:trojan-activity; sid:100001354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"20.185.42.197"; classtype:trojan-activity; sid:100001355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.104.150.167"; classtype:trojan-activity; sid:100001356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.105.167.98"; classtype:trojan-activity; sid:100001357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.111.189.70"; classtype:trojan-activity; sid:100001358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.194.4.24"; classtype:trojan-activity; sid:100001359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.2.161.171"; classtype:trojan-activity; sid:100001360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.30.132.50"; classtype:trojan-activity; sid:100001361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.142.147.89"; classtype:trojan-activity; sid:100001362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.170.46.2"; classtype:trojan-activity; sid:100001363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.184.163.170"; classtype:trojan-activity; sid:100001364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.187.102.73"; classtype:trojan-activity; sid:100001365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.200.254.86"; classtype:trojan-activity; sid:100001366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.203.27.37"; classtype:trojan-activity; sid:100001367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.205.12.170"; classtype:trojan-activity; sid:100001368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.107.233.41"; classtype:trojan-activity; sid:100001369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.150.176.100"; classtype:trojan-activity; sid:100001370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.166.217.54"; classtype:trojan-activity; sid:100001371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.175.103.10"; classtype:trojan-activity; sid:100001372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.29.95.12"; classtype:trojan-activity; sid:100001373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.4.124.58"; classtype:trojan-activity; sid:100001374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.176.114"; classtype:trojan-activity; sid:100001375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.191.174"; classtype:trojan-activity; sid:100001376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.74.236.9"; classtype:trojan-activity; sid:100001377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.109.201.243"; classtype:trojan-activity; sid:100001378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.170.123.78"; classtype:trojan-activity; sid:100001379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.204.232.18"; classtype:trojan-activity; sid:100001380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.229.21.56"; classtype:trojan-activity; sid:100001381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.236.190.28"; classtype:trojan-activity; sid:100001382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.238.86.202"; classtype:trojan-activity; sid:100001383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.243.142.132"; classtype:trojan-activity; sid:100001384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.70.166.107"; classtype:trojan-activity; sid:100001385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.77.80.159"; classtype:trojan-activity; sid:100001386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.119.166"; classtype:trojan-activity; sid:100001387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.171.138"; classtype:trojan-activity; sid:100001388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.82.36.34"; classtype:trojan-activity; sid:100001389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.93.6.28"; classtype:trojan-activity; sid:100001390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"204.195.116.171"; classtype:trojan-activity; sid:100001391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"205.185.115.74"; classtype:trojan-activity; sid:100001392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"205.185.116.94"; classtype:trojan-activity; sid:100001393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"205.185.123.217"; classtype:trojan-activity; sid:100001394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"206.248.137.132"; classtype:trojan-activity; sid:100001395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"206.47.41.166"; classtype:trojan-activity; sid:100001396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.180.228.101"; classtype:trojan-activity; sid:100001397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.5.32.6"; classtype:trojan-activity; sid:100001398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"208.163.58.18"; classtype:trojan-activity; sid:100001399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"208.75.27.157"; classtype:trojan-activity; sid:100001400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.39.50"; classtype:trojan-activity; sid:100001401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.190"; classtype:trojan-activity; sid:100001402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.31"; classtype:trojan-activity; sid:100001403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.46.87"; classtype:trojan-activity; sid:100001404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.124.149.19"; classtype:trojan-activity; sid:100001405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.152.122"; classtype:trojan-activity; sid:100001406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.153.142"; classtype:trojan-activity; sid:100001407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.234.93"; classtype:trojan-activity; sid:100001408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.237.70"; classtype:trojan-activity; sid:100001409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.245.109"; classtype:trojan-activity; sid:100001410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.68.242.114"; classtype:trojan-activity; sid:100001411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.96.116.236"; classtype:trojan-activity; sid:100001412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.116.220.37"; classtype:trojan-activity; sid:100001413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.132.204"; classtype:trojan-activity; sid:100001414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.75.220"; classtype:trojan-activity; sid:100001415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.200.160.239"; classtype:trojan-activity; sid:100001416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.204.215.157"; classtype:trojan-activity; sid:100001417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.66.179"; classtype:trojan-activity; sid:100001418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.93.93"; classtype:trojan-activity; sid:100001419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.216.66.105"; classtype:trojan-activity; sid:100001420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.114.96"; classtype:trojan-activity; sid:100001421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.120.13"; classtype:trojan-activity; sid:100001422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.246.137"; classtype:trojan-activity; sid:100001423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.238.83.238"; classtype:trojan-activity; sid:100001424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.247.113.49"; classtype:trojan-activity; sid:100001425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.247.5.96"; classtype:trojan-activity; sid:100001426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.32.122.110"; classtype:trojan-activity; sid:100001427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.122.86.105"; classtype:trojan-activity; sid:100001428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.143.227.22"; classtype:trojan-activity; sid:100001429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.156.215.178"; classtype:trojan-activity; sid:100001430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.46.197.114"; classtype:trojan-activity; sid:100001431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.56.197.230"; classtype:trojan-activity; sid:100001432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.8.251.211"; classtype:trojan-activity; sid:100001433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.123.206.197"; classtype:trojan-activity; sid:100001434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.135.178.253"; classtype:trojan-activity; sid:100001435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.14.173.117"; classtype:trojan-activity; sid:100001436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.149.182.113"; classtype:trojan-activity; sid:100001437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.149.190.193"; classtype:trojan-activity; sid:100001438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.12"; classtype:trojan-activity; sid:100001439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.99"; classtype:trojan-activity; sid:100001440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.135"; classtype:trojan-activity; sid:100001441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.20"; classtype:trojan-activity; sid:100001442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.237"; classtype:trojan-activity; sid:100001443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.6"; classtype:trojan-activity; sid:100001444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.114.165"; classtype:trojan-activity; sid:100001445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.105"; classtype:trojan-activity; sid:100001446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.11"; classtype:trojan-activity; sid:100001447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.15"; classtype:trojan-activity; sid:100001448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.30"; classtype:trojan-activity; sid:100001449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.71"; classtype:trojan-activity; sid:100001450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.192"; classtype:trojan-activity; sid:100001451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.117.151"; classtype:trojan-activity; sid:100001452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.238"; classtype:trojan-activity; sid:100001453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.65"; classtype:trojan-activity; sid:100001454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.119.236"; classtype:trojan-activity; sid:100001455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.175"; classtype:trojan-activity; sid:100001456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.7"; classtype:trojan-activity; sid:100001457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.107"; classtype:trojan-activity; sid:100001458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.46"; classtype:trojan-activity; sid:100001459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.189.178.163"; classtype:trojan-activity; sid:100001460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.240.218.15"; classtype:trojan-activity; sid:100001461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.249.156.189"; classtype:trojan-activity; sid:100001462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.27.8.6"; classtype:trojan-activity; sid:100001463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.254.52"; classtype:trojan-activity; sid:100001464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.255.36"; classtype:trojan-activity; sid:100001465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.255.84"; classtype:trojan-activity; sid:100001466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.127.185.150"; classtype:trojan-activity; sid:100001467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.158.238.236"; classtype:trojan-activity; sid:100001468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.170.240.98"; classtype:trojan-activity; sid:100001469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.183.54.169"; classtype:trojan-activity; sid:100001470; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.36.12.98"; classtype:trojan-activity; sid:100001471; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"217.11.75.162"; classtype:trojan-activity; sid:100001472; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.12.181.110"; classtype:trojan-activity; sid:100001473; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.2.40.34"; classtype:trojan-activity; sid:100001474; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.234.165.18"; classtype:trojan-activity; sid:100001475; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.238.246.3"; classtype:trojan-activity; sid:100001476; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.28.160.174"; classtype:trojan-activity; sid:100001477; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.207.119"; classtype:trojan-activity; sid:100001478; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.227.133"; classtype:trojan-activity; sid:100001479; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.68.35"; classtype:trojan-activity; sid:100001480; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.81.81"; classtype:trojan-activity; sid:100001481; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.56.93.129"; classtype:trojan-activity; sid:100001482; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.58.92.253"; classtype:trojan-activity; sid:100001483; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.59.116.203"; classtype:trojan-activity; sid:100001484; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.72.207.116"; classtype:trojan-activity; sid:100001485; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.79.103.159"; classtype:trojan-activity; sid:100001486; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.93.102.63"; classtype:trojan-activity; sid:100001487; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.93.102.75"; classtype:trojan-activity; sid:100001488; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.102.14"; classtype:trojan-activity; sid:100001489; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.11.207"; classtype:trojan-activity; sid:100001490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.12.85"; classtype:trojan-activity; sid:100001491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.26.190"; classtype:trojan-activity; sid:100001492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.29.165"; classtype:trojan-activity; sid:100001493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.186.18"; classtype:trojan-activity; sid:100001494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.139.165"; classtype:trojan-activity; sid:100001495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.150.91"; classtype:trojan-activity; sid:100001496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.214.235"; classtype:trojan-activity; sid:100001497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.50.106"; classtype:trojan-activity; sid:100001498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.241.6.180"; classtype:trojan-activity; sid:100001499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.1.148"; classtype:trojan-activity; sid:100001500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.1.84"; classtype:trojan-activity; sid:100001501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.163.7"; classtype:trojan-activity; sid:100001502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.171.144"; classtype:trojan-activity; sid:100001503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.245.63"; classtype:trojan-activity; sid:100001504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.5.140"; classtype:trojan-activity; sid:100001505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.69.71.186"; classtype:trojan-activity; sid:100001506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.80.217.209"; classtype:trojan-activity; sid:100001507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.85.145.194"; classtype:trojan-activity; sid:100001508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"21robo.com"; classtype:trojan-activity; sid:100001509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.118.168.155"; classtype:trojan-activity; sid:100001510; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.126.237.74"; classtype:trojan-activity; sid:100001511; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.200.22.163"; classtype:trojan-activity; sid:100001512; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.247.91.17"; classtype:trojan-activity; sid:100001513; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.71.239.115"; classtype:trojan-activity; sid:100001514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.90.159.188"; classtype:trojan-activity; sid:100001515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.1.144.183"; classtype:trojan-activity; sid:100001516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.124.78.15"; classtype:trojan-activity; sid:100001517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.113.234"; classtype:trojan-activity; sid:100001518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.157.191.178"; classtype:trojan-activity; sid:100001519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.136.213"; classtype:trojan-activity; sid:100001520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.202.232.230"; classtype:trojan-activity; sid:100001521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.130.147"; classtype:trojan-activity; sid:100001522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.251.109"; classtype:trojan-activity; sid:100001523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.116.167"; classtype:trojan-activity; sid:100001524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.172.207"; classtype:trojan-activity; sid:100001525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.184.31"; classtype:trojan-activity; sid:100001526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.252.64"; classtype:trojan-activity; sid:100001527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.8.64"; classtype:trojan-activity; sid:100001528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.232.1.82"; classtype:trojan-activity; sid:100001529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.235.137.36"; classtype:trojan-activity; sid:100001530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.112.125"; classtype:trojan-activity; sid:100001531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.32.88"; classtype:trojan-activity; sid:100001532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.34.43"; classtype:trojan-activity; sid:100001533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.43.223"; classtype:trojan-activity; sid:100001534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.68.16"; classtype:trojan-activity; sid:100001535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.108.17.64"; classtype:trojan-activity; sid:100001536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.118.248.149"; classtype:trojan-activity; sid:100001537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.119.65.145"; classtype:trojan-activity; sid:100001538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.132.125.138"; classtype:trojan-activity; sid:100001539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.103.120"; classtype:trojan-activity; sid:100001540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.67.115"; classtype:trojan-activity; sid:100001541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.9.5"; classtype:trojan-activity; sid:100001542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.148.192"; classtype:trojan-activity; sid:100001543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.211.78"; classtype:trojan-activity; sid:100001544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.17.132"; classtype:trojan-activity; sid:100001545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.237.155"; classtype:trojan-activity; sid:100001546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.17.245"; classtype:trojan-activity; sid:100001547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.162.187.43"; classtype:trojan-activity; sid:100001548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.179.215.189"; classtype:trojan-activity; sid:100001549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.185.116.233"; classtype:trojan-activity; sid:100001550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.187.9.178"; classtype:trojan-activity; sid:100001551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.211.72.66"; classtype:trojan-activity; sid:100001552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.236.85.220"; classtype:trojan-activity; sid:100001553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.238.230.7"; classtype:trojan-activity; sid:100001554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.239.83.232"; classtype:trojan-activity; sid:100001555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.248.64.253"; classtype:trojan-activity; sid:100001556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.92.9.126"; classtype:trojan-activity; sid:100001557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.95.190.20"; classtype:trojan-activity; sid:100001558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.99.171.192"; classtype:trojan-activity; sid:100001559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.131.201.82"; classtype:trojan-activity; sid:100001560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.166.117.210"; classtype:trojan-activity; sid:100001561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.167.118.17"; classtype:trojan-activity; sid:100001562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.225.68"; classtype:trojan-activity; sid:100001563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.234.84"; classtype:trojan-activity; sid:100001564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.5.29"; classtype:trojan-activity; sid:100001565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.73.175"; classtype:trojan-activity; sid:100001566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.115.118.232"; classtype:trojan-activity; sid:100001567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.125.186.135"; classtype:trojan-activity; sid:100001568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.126.120.25"; classtype:trojan-activity; sid:100001569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.228.143.58"; classtype:trojan-activity; sid:100001570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.24.213.121"; classtype:trojan-activity; sid:100001571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.149.13"; classtype:trojan-activity; sid:100001572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.21.167"; classtype:trojan-activity; sid:100001573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.95.89.21"; classtype:trojan-activity; sid:100001574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.103.74.180"; classtype:trojan-activity; sid:100001575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.11.141.134"; classtype:trojan-activity; sid:100001576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.119.158.74"; classtype:trojan-activity; sid:100001577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.137.147.95"; classtype:trojan-activity; sid:100001578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.137.233.132"; classtype:trojan-activity; sid:100001579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.152.235.88"; classtype:trojan-activity; sid:100001580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.158.25.98"; classtype:trojan-activity; sid:100001581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.176.206.12"; classtype:trojan-activity; sid:100001582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.184.1.41"; classtype:trojan-activity; sid:100001583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.192.191.109"; classtype:trojan-activity; sid:100001584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.225.114.161"; classtype:trojan-activity; sid:100001585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.227.190.78"; classtype:trojan-activity; sid:100001586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.35.245.52"; classtype:trojan-activity; sid:100001587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.39.181.18"; classtype:trojan-activity; sid:100001588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.39.34.242"; classtype:trojan-activity; sid:100001589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.42.229.143"; classtype:trojan-activity; sid:100001590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.45.4.1"; classtype:trojan-activity; sid:100001591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.51.91.113"; classtype:trojan-activity; sid:100001592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.53.163.10"; classtype:trojan-activity; sid:100001593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.53.163.9"; classtype:trojan-activity; sid:100001594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.89.140.190"; classtype:trojan-activity; sid:100001595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.1.245.16"; classtype:trojan-activity; sid:100001596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.1.245.7"; classtype:trojan-activity; sid:100001597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.105.106.201"; classtype:trojan-activity; sid:100001598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.105.152.107"; classtype:trojan-activity; sid:100001599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.116.84.57"; classtype:trojan-activity; sid:100001600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.14.81.201"; classtype:trojan-activity; sid:100001601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.141.218.17"; classtype:trojan-activity; sid:100001602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.147.29.52"; classtype:trojan-activity; sid:100001603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.147.40.128"; classtype:trojan-activity; sid:100001604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.184.251.135"; classtype:trojan-activity; sid:100001605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.193.196.190"; classtype:trojan-activity; sid:100001606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.193.217.210"; classtype:trojan-activity; sid:100001607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.149.142"; classtype:trojan-activity; sid:100001608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.159.98"; classtype:trojan-activity; sid:100001609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.192.66"; classtype:trojan-activity; sid:100001610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.210.20"; classtype:trojan-activity; sid:100001611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.22.217"; classtype:trojan-activity; sid:100001612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.23.215"; classtype:trojan-activity; sid:100001613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.232.65"; classtype:trojan-activity; sid:100001614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.3.194"; classtype:trojan-activity; sid:100001615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.34.48"; classtype:trojan-activity; sid:100001616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.110.211"; classtype:trojan-activity; sid:100001617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.140.229"; classtype:trojan-activity; sid:100001618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.32.146"; classtype:trojan-activity; sid:100001619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.201.183.149"; classtype:trojan-activity; sid:100001620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.202.182.201"; classtype:trojan-activity; sid:100001621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.102.12"; classtype:trojan-activity; sid:100001622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.116.86"; classtype:trojan-activity; sid:100001623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.154.105"; classtype:trojan-activity; sid:100001624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.165.138"; classtype:trojan-activity; sid:100001625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.185.42"; classtype:trojan-activity; sid:100001626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.213.79"; classtype:trojan-activity; sid:100001627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.255.42"; classtype:trojan-activity; sid:100001628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.28.115"; classtype:trojan-activity; sid:100001629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.4.188"; classtype:trojan-activity; sid:100001630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.68.144"; classtype:trojan-activity; sid:100001631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.7.141"; classtype:trojan-activity; sid:100001632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.87.75"; classtype:trojan-activity; sid:100001633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.94.134"; classtype:trojan-activity; sid:100001634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.204.253.74"; classtype:trojan-activity; sid:100001635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.205.178.110"; classtype:trojan-activity; sid:100001636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.136.101"; classtype:trojan-activity; sid:100001637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.154.122"; classtype:trojan-activity; sid:100001638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.80.209"; classtype:trojan-activity; sid:100001639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.151.126"; classtype:trojan-activity; sid:100001640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.155.31"; classtype:trojan-activity; sid:100001641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.170.203"; classtype:trojan-activity; sid:100001642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.119.27"; classtype:trojan-activity; sid:100001643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.152.10"; classtype:trojan-activity; sid:100001644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.160.177"; classtype:trojan-activity; sid:100001645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.164.18"; classtype:trojan-activity; sid:100001646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.237.105"; classtype:trojan-activity; sid:100001647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.247.130"; classtype:trojan-activity; sid:100001648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.25.59"; classtype:trojan-activity; sid:100001649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.34.2"; classtype:trojan-activity; sid:100001650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.92.64"; classtype:trojan-activity; sid:100001651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.208.122"; classtype:trojan-activity; sid:100001652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.231.15"; classtype:trojan-activity; sid:100001653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.107.125"; classtype:trojan-activity; sid:100001654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.172.245"; classtype:trojan-activity; sid:100001655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.234.28"; classtype:trojan-activity; sid:100001656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.236.134"; classtype:trojan-activity; sid:100001657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.44.19"; classtype:trojan-activity; sid:100001658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.63.243"; classtype:trojan-activity; sid:100001659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.104.201"; classtype:trojan-activity; sid:100001660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.109.58"; classtype:trojan-activity; sid:100001661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.175.208"; classtype:trojan-activity; sid:100001662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.255.202"; classtype:trojan-activity; sid:100001663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.66.112"; classtype:trojan-activity; sid:100001664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.84.74"; classtype:trojan-activity; sid:100001665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.214.37.129"; classtype:trojan-activity; sid:100001666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.139.242"; classtype:trojan-activity; sid:100001667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.190.172"; classtype:trojan-activity; sid:100001668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.212.209"; classtype:trojan-activity; sid:100001669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.253.149"; classtype:trojan-activity; sid:100001670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.34.242"; classtype:trojan-activity; sid:100001671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.71.243"; classtype:trojan-activity; sid:100001672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.98.242"; classtype:trojan-activity; sid:100001673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.128.156"; classtype:trojan-activity; sid:100001674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.131.66"; classtype:trojan-activity; sid:100001675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.144.66"; classtype:trojan-activity; sid:100001676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.197.193"; classtype:trojan-activity; sid:100001677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.225.28"; classtype:trojan-activity; sid:100001678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.227.95"; classtype:trojan-activity; sid:100001679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.234.98"; classtype:trojan-activity; sid:100001680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.133.53"; classtype:trojan-activity; sid:100001681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.191.58"; classtype:trojan-activity; sid:100001682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.248.121"; classtype:trojan-activity; sid:100001683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.132.71"; classtype:trojan-activity; sid:100001684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.151.83"; classtype:trojan-activity; sid:100001685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.160.112"; classtype:trojan-activity; sid:100001686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.176.72"; classtype:trojan-activity; sid:100001687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.192.223"; classtype:trojan-activity; sid:100001688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.83.244"; classtype:trojan-activity; sid:100001689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.20.66"; classtype:trojan-activity; sid:100001690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.249.0"; classtype:trojan-activity; sid:100001691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.85.168"; classtype:trojan-activity; sid:100001692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.221.239.223"; classtype:trojan-activity; sid:100001693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.241.223"; classtype:trojan-activity; sid:100001694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.249.210"; classtype:trojan-activity; sid:100001695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.76.80"; classtype:trojan-activity; sid:100001696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.223.242.164"; classtype:trojan-activity; sid:100001697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.24.28.134"; classtype:trojan-activity; sid:100001698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.129.198"; classtype:trojan-activity; sid:100001699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.154.13"; classtype:trojan-activity; sid:100001700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.16.145"; classtype:trojan-activity; sid:100001701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.2.30"; classtype:trojan-activity; sid:100001702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.212.124"; classtype:trojan-activity; sid:100001703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.58.5"; classtype:trojan-activity; sid:100001704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.237.129"; classtype:trojan-activity; sid:100001705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.43.117.98"; classtype:trojan-activity; sid:100001706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.0.98.131"; classtype:trojan-activity; sid:100001707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.11.51.57"; classtype:trojan-activity; sid:100001708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.13.23.180"; classtype:trojan-activity; sid:100001709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.124.130"; classtype:trojan-activity; sid:100001710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.179.83"; classtype:trojan-activity; sid:100001711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.184.59"; classtype:trojan-activity; sid:100001712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.191.243"; classtype:trojan-activity; sid:100001713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.194.67"; classtype:trojan-activity; sid:100001714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.216.132"; classtype:trojan-activity; sid:100001715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.219.28"; classtype:trojan-activity; sid:100001716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.24.115"; classtype:trojan-activity; sid:100001717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.30.65"; classtype:trojan-activity; sid:100001718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.63.203"; classtype:trojan-activity; sid:100001719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.65.233"; classtype:trojan-activity; sid:100001720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.79.66"; classtype:trojan-activity; sid:100001721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.94.16"; classtype:trojan-activity; sid:100001722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.179.201.26"; classtype:trojan-activity; sid:100001723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.195.84.250"; classtype:trojan-activity; sid:100001724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.177"; classtype:trojan-activity; sid:100001725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.69"; classtype:trojan-activity; sid:100001726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.28.7.159"; classtype:trojan-activity; sid:100001727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.30.119.23"; classtype:trojan-activity; sid:100001728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32.208.157.193"; classtype:trojan-activity; sid:100001729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32792.prolocksmithwinterpark.com"; classtype:trojan-activity; sid:100001730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"35.184.169.169"; classtype:trojan-activity; sid:100001731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.107.209.10"; classtype:trojan-activity; sid:100001732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.108.231.218"; classtype:trojan-activity; sid:100001733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.248.228.64"; classtype:trojan-activity; sid:100001734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.250.203.246"; classtype:trojan-activity; sid:100001735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.157.225"; classtype:trojan-activity; sid:100001736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.18.18"; classtype:trojan-activity; sid:100001737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.51.244"; classtype:trojan-activity; sid:100001738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.255.90.219"; classtype:trojan-activity; sid:100001739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.33.160.167"; classtype:trojan-activity; sid:100001740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.34.150.236"; classtype:trojan-activity; sid:100001741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.105.159"; classtype:trojan-activity; sid:100001742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.111.203"; classtype:trojan-activity; sid:100001743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.139.36"; classtype:trojan-activity; sid:100001744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.89.18.133"; classtype:trojan-activity; sid:100001745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360.lcy2zzx.pw"; classtype:trojan-activity; sid:100001746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360down7.miiyun.cn"; classtype:trojan-activity; sid:100001747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.222.98.51"; classtype:trojan-activity; sid:100001748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.233.60.68"; classtype:trojan-activity; sid:100001749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.179.221"; classtype:trojan-activity; sid:100001750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.180.172"; classtype:trojan-activity; sid:100001751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.44.238.35"; classtype:trojan-activity; sid:100001752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.49.230.177"; classtype:trojan-activity; sid:100001753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.14.36"; classtype:trojan-activity; sid:100001754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.14.52"; classtype:trojan-activity; sid:100001755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.230.61"; classtype:trojan-activity; sid:100001756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"38.77.14.237"; classtype:trojan-activity; sid:100001757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.245.254"; classtype:trojan-activity; sid:100001758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.98.136"; classtype:trojan-activity; sid:100001759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.117.31.162"; classtype:trojan-activity; sid:100001760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.162.104.119"; classtype:trojan-activity; sid:100001761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.196.34"; classtype:trojan-activity; sid:100001762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.59.160"; classtype:trojan-activity; sid:100001763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.66.44.109"; classtype:trojan-activity; sid:100001764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.104.83"; classtype:trojan-activity; sid:100001765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.125.186"; classtype:trojan-activity; sid:100001766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.146.60"; classtype:trojan-activity; sid:100001767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.148.163"; classtype:trojan-activity; sid:100001768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.206.228"; classtype:trojan-activity; sid:100001769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.124.76"; classtype:trojan-activity; sid:100001770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.171.125"; classtype:trojan-activity; sid:100001771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.249.255"; classtype:trojan-activity; sid:100001772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.60.61"; classtype:trojan-activity; sid:100001773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.167.202"; classtype:trojan-activity; sid:100001774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.67.64"; classtype:trojan-activity; sid:100001775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.10.198"; classtype:trojan-activity; sid:100001776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.163.231"; classtype:trojan-activity; sid:100001777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.168.234"; classtype:trojan-activity; sid:100001778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.203.225"; classtype:trojan-activity; sid:100001779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.237.84"; classtype:trojan-activity; sid:100001780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.132.170"; classtype:trojan-activity; sid:100001781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.194.65"; classtype:trojan-activity; sid:100001782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.235.122"; classtype:trojan-activity; sid:100001783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.33.191"; classtype:trojan-activity; sid:100001784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.78.251"; classtype:trojan-activity; sid:100001785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.113.201"; classtype:trojan-activity; sid:100001786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.114.45"; classtype:trojan-activity; sid:100001787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.14.27"; classtype:trojan-activity; sid:100001788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.150.203"; classtype:trojan-activity; sid:100001789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.197.81"; classtype:trojan-activity; sid:100001790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.209.209"; classtype:trojan-activity; sid:100001791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.48.213"; classtype:trojan-activity; sid:100001792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.63.152"; classtype:trojan-activity; sid:100001793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.94.189"; classtype:trojan-activity; sid:100001794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.163.188"; classtype:trojan-activity; sid:100001795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.166.31"; classtype:trojan-activity; sid:100001796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.218.46"; classtype:trojan-activity; sid:100001797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.91.244"; classtype:trojan-activity; sid:100001798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.93.171"; classtype:trojan-activity; sid:100001799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.127.214"; classtype:trojan-activity; sid:100001800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.18.140"; classtype:trojan-activity; sid:100001801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.191.137"; classtype:trojan-activity; sid:100001802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.205.255"; classtype:trojan-activity; sid:100001803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.24.54"; classtype:trojan-activity; sid:100001804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.36.151"; classtype:trojan-activity; sid:100001805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.37.182"; classtype:trojan-activity; sid:100001806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.251.0"; classtype:trojan-activity; sid:100001807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.27.15"; classtype:trojan-activity; sid:100001808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.29.231"; classtype:trojan-activity; sid:100001809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.70.88"; classtype:trojan-activity; sid:100001810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.83.94.11"; classtype:trojan-activity; sid:100001811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.115.152"; classtype:trojan-activity; sid:100001812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.85.54.191"; classtype:trojan-activity; sid:100001813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.85.54.4"; classtype:trojan-activity; sid:100001814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.129.233"; classtype:trojan-activity; sid:100001815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.170.209"; classtype:trojan-activity; sid:100001816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.211.20"; classtype:trojan-activity; sid:100001817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.234.187"; classtype:trojan-activity; sid:100001818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.63.58"; classtype:trojan-activity; sid:100001819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.93.109"; classtype:trojan-activity; sid:100001820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.155.96"; classtype:trojan-activity; sid:100001821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.233.131"; classtype:trojan-activity; sid:100001822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.67.238"; classtype:trojan-activity; sid:100001823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.108.109"; classtype:trojan-activity; sid:100001824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.145.11"; classtype:trojan-activity; sid:100001825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.146.198"; classtype:trojan-activity; sid:100001826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.146.36"; classtype:trojan-activity; sid:100001827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.63.23"; classtype:trojan-activity; sid:100001828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.90.86.212"; classtype:trojan-activity; sid:100001829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"40.88.2.151"; classtype:trojan-activity; sid:100001830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.139.209.46"; classtype:trojan-activity; sid:100001831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.165.130.43"; classtype:trojan-activity; sid:100001832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.190.63.174"; classtype:trojan-activity; sid:100001833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.193.192.100"; classtype:trojan-activity; sid:100001834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.219.185.171"; classtype:trojan-activity; sid:100001835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.226.60.115"; classtype:trojan-activity; sid:100001836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.72.203.82"; classtype:trojan-activity; sid:100001837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.169"; classtype:trojan-activity; sid:100001838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.23"; classtype:trojan-activity; sid:100001839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.27"; classtype:trojan-activity; sid:100001840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.38"; classtype:trojan-activity; sid:100001841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.202.101.199"; classtype:trojan-activity; sid:100001842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.43.161"; classtype:trojan-activity; sid:100001843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.65.104"; classtype:trojan-activity; sid:100001844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.82.176"; classtype:trojan-activity; sid:100001845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.180.147"; classtype:trojan-activity; sid:100001846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.239.26.122"; classtype:trojan-activity; sid:100001847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.56.15.227"; classtype:trojan-activity; sid:100001848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.61.99.155"; classtype:trojan-activity; sid:100001849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.82.217.241"; classtype:trojan-activity; sid:100001850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.84.37.198"; classtype:trojan-activity; sid:100001851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.241.106.183"; classtype:trojan-activity; sid:100001852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.241.108.134"; classtype:trojan-activity; sid:100001853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.252.8.94"; classtype:trojan-activity; sid:100001854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.115.172.148"; classtype:trojan-activity; sid:100001855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.1.242"; classtype:trojan-activity; sid:100001856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.203.192"; classtype:trojan-activity; sid:100001857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.135.134.228"; classtype:trojan-activity; sid:100001858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.204"; classtype:trojan-activity; sid:100001859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.141.84.184"; classtype:trojan-activity; sid:100001860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.118"; classtype:trojan-activity; sid:100001861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.135"; classtype:trojan-activity; sid:100001862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.139"; classtype:trojan-activity; sid:100001863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.196"; classtype:trojan-activity; sid:100001864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.213"; classtype:trojan-activity; sid:100001865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.242"; classtype:trojan-activity; sid:100001866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.27"; classtype:trojan-activity; sid:100001867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.65"; classtype:trojan-activity; sid:100001868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.47"; classtype:trojan-activity; sid:100001869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.94"; classtype:trojan-activity; sid:100001870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.164.140.130"; classtype:trojan-activity; sid:100001871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.165.215.19"; classtype:trojan-activity; sid:100001872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.151"; classtype:trojan-activity; sid:100001873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.22"; classtype:trojan-activity; sid:100001874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.248"; classtype:trojan-activity; sid:100001875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.110.99"; classtype:trojan-activity; sid:100001876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.22.209.58"; classtype:trojan-activity; sid:100001877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.229.53.115"; classtype:trojan-activity; sid:100001878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.23.22.186"; classtype:trojan-activity; sid:100001879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.248.194.48"; classtype:trojan-activity; sid:100001880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.27.253.137"; classtype:trojan-activity; sid:100001881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.51.104.59"; classtype:trojan-activity; sid:100001882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.6.24.251"; classtype:trojan-activity; sid:100001883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.81.235.31"; classtype:trojan-activity; sid:100001884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.85.90.131"; classtype:trojan-activity; sid:100001885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.85.90.179"; classtype:trojan-activity; sid:100001886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.85.90.203"; classtype:trojan-activity; sid:100001887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.9.148.37"; classtype:trojan-activity; sid:100001888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.92.108.125"; classtype:trojan-activity; sid:100001889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.95.169.153"; classtype:trojan-activity; sid:100001890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.117.42.29"; classtype:trojan-activity; sid:100001891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.172.75.231"; classtype:trojan-activity; sid:100001892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.182.173.246"; classtype:trojan-activity; sid:100001893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.182.173.247"; classtype:trojan-activity; sid:100001894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.20.63.218"; classtype:trojan-activity; sid:100001895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.214.27.4"; classtype:trojan-activity; sid:100001896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.24.130.254"; classtype:trojan-activity; sid:100001897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.241.120.165"; classtype:trojan-activity; sid:100001898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.243.179.115"; classtype:trojan-activity; sid:100001899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.249.33.79"; classtype:trojan-activity; sid:100001900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.25.242.211"; classtype:trojan-activity; sid:100001901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.118.86"; classtype:trojan-activity; sid:100001902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.86.128"; classtype:trojan-activity; sid:100001903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.97.76.242"; classtype:trojan-activity; sid:100001904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.103.219.77"; classtype:trojan-activity; sid:100001905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.145.152.26"; classtype:trojan-activity; sid:100001906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.151.23.172"; classtype:trojan-activity; sid:100001907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.157.97.71"; classtype:trojan-activity; sid:100001908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.16.131.51"; classtype:trojan-activity; sid:100001909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.21.202.98"; classtype:trojan-activity; sid:100001910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.46.231.38"; classtype:trojan-activity; sid:100001911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.162.113"; classtype:trojan-activity; sid:100001912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.87.36"; classtype:trojan-activity; sid:100001913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.143.43.93"; classtype:trojan-activity; sid:100001914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.156.35.166"; classtype:trojan-activity; sid:100001915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.158.201.200"; classtype:trojan-activity; sid:100001916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.20.121"; classtype:trojan-activity; sid:100001917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.21.3"; classtype:trojan-activity; sid:100001918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.174.182.99"; classtype:trojan-activity; sid:100001919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.170.49"; classtype:trojan-activity; sid:100001920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.178.183"; classtype:trojan-activity; sid:100001921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.179.129"; classtype:trojan-activity; sid:100001922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.68.221.252"; classtype:trojan-activity; sid:100001923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.188.62.111"; classtype:trojan-activity; sid:100001924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.2.70.50"; classtype:trojan-activity; sid:100001925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.42.37.74"; classtype:trojan-activity; sid:100001926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.53.146.179"; classtype:trojan-activity; sid:100001927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.79.75.210"; classtype:trojan-activity; sid:100001928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.95.226.154"; classtype:trojan-activity; sid:100001929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.115.174.102"; classtype:trojan-activity; sid:100001930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.115.174.106"; classtype:trojan-activity; sid:100001931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.121.91.255"; classtype:trojan-activity; sid:100001932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.252.47.29"; classtype:trojan-activity; sid:100001933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"51.222.56.159"; classtype:trojan-activity; sid:100001934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.114.136"; classtype:trojan-activity; sid:100001935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.180.122"; classtype:trojan-activity; sid:100001936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.114.246.26"; classtype:trojan-activity; sid:100001937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.162.92"; classtype:trojan-activity; sid:100001938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.174.4"; classtype:trojan-activity; sid:100001939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.125.191.4"; classtype:trojan-activity; sid:100001940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.126.247.118"; classtype:trojan-activity; sid:100001941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.141.122.109"; classtype:trojan-activity; sid:100001942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.166.120"; classtype:trojan-activity; sid:100001943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.200.124"; classtype:trojan-activity; sid:100001944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.143.189.75"; classtype:trojan-activity; sid:100001945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.218.67.253"; classtype:trojan-activity; sid:100001946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.22.212.107"; classtype:trojan-activity; sid:100001947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.226.129.29"; classtype:trojan-activity; sid:100001948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.229.194.122"; classtype:trojan-activity; sid:100001949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.230.89.42"; classtype:trojan-activity; sid:100001950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.238.42.192"; classtype:trojan-activity; sid:100001951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.240.147.97"; classtype:trojan-activity; sid:100001952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.241.78.55"; classtype:trojan-activity; sid:100001953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.243.123.212"; classtype:trojan-activity; sid:100001954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.243.126.133"; classtype:trojan-activity; sid:100001955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.243.208.225"; classtype:trojan-activity; sid:100001956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.118.64"; classtype:trojan-activity; sid:100001957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.80.181"; classtype:trojan-activity; sid:100001958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.48.154.143"; classtype:trojan-activity; sid:100001959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.153"; classtype:trojan-activity; sid:100001960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.39"; classtype:trojan-activity; sid:100001961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.76.151.51"; classtype:trojan-activity; sid:100001962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.97.206.33"; classtype:trojan-activity; sid:100001963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.0.211.161"; classtype:trojan-activity; sid:100001964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.102.168.189"; classtype:trojan-activity; sid:100001965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.202.3"; classtype:trojan-activity; sid:100001966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.207.150"; classtype:trojan-activity; sid:100001967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.214.4"; classtype:trojan-activity; sid:100001968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.237.51"; classtype:trojan-activity; sid:100001969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.246.125"; classtype:trojan-activity; sid:100001970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.23.114.97"; classtype:trojan-activity; sid:100001971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.58.117.226"; classtype:trojan-activity; sid:100001972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.10.91.242"; classtype:trojan-activity; sid:100001973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.13.61.12"; classtype:trojan-activity; sid:100001974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.164.130.220"; classtype:trojan-activity; sid:100001975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.175.124.27"; classtype:trojan-activity; sid:100001976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.20.217.142"; classtype:trojan-activity; sid:100001977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.208.135.42"; classtype:trojan-activity; sid:100001978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.122.57"; classtype:trojan-activity; sid:100001979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.186.185"; classtype:trojan-activity; sid:100001980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.216.23"; classtype:trojan-activity; sid:100001981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.233.94"; classtype:trojan-activity; sid:100001982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.6.112"; classtype:trojan-activity; sid:100001983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.100.83"; classtype:trojan-activity; sid:100001984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.111.39"; classtype:trojan-activity; sid:100001985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.202.218"; classtype:trojan-activity; sid:100001986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.206.246"; classtype:trojan-activity; sid:100001987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.218.31"; classtype:trojan-activity; sid:100001988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.220.167"; classtype:trojan-activity; sid:100001989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.254.178"; classtype:trojan-activity; sid:100001990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.162.59"; classtype:trojan-activity; sid:100001991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.83.55"; classtype:trojan-activity; sid:100001992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.195.111"; classtype:trojan-activity; sid:100001993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.177.196"; classtype:trojan-activity; sid:100001994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.86.208"; classtype:trojan-activity; sid:100001995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.223.84.102"; classtype:trojan-activity; sid:100001996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.25.109.240"; classtype:trojan-activity; sid:100001997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.15.104"; classtype:trojan-activity; sid:100001998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.39.88"; classtype:trojan-activity; sid:100001999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.4.72"; classtype:trojan-activity; sid:100002000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.51.127"; classtype:trojan-activity; sid:100002001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.60.174"; classtype:trojan-activity; sid:100002002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.8.81"; classtype:trojan-activity; sid:100002003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.26.104.150"; classtype:trojan-activity; sid:100002004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.10.121"; classtype:trojan-activity; sid:100002005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.8.43"; classtype:trojan-activity; sid:100002006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.99.254"; classtype:trojan-activity; sid:100002007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.164.96.98"; classtype:trojan-activity; sid:100002008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.171.60"; classtype:trojan-activity; sid:100002009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.91.194"; classtype:trojan-activity; sid:100002010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.247.224.66"; classtype:trojan-activity; sid:100002011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.253.94.230"; classtype:trojan-activity; sid:100002012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.3.149.112"; classtype:trojan-activity; sid:100002013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.41.230.161"; classtype:trojan-activity; sid:100002014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.47.220.169"; classtype:trojan-activity; sid:100002015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.103.217"; classtype:trojan-activity; sid:100002016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.199.47"; classtype:trojan-activity; sid:100002017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.207.10"; classtype:trojan-activity; sid:100002018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.30.172"; classtype:trojan-activity; sid:100002019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.9.166"; classtype:trojan-activity; sid:100002020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.9.62"; classtype:trojan-activity; sid:100002021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.99.161"; classtype:trojan-activity; sid:100002022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.102.137"; classtype:trojan-activity; sid:100002023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.117.237"; classtype:trojan-activity; sid:100002024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.220.0"; classtype:trojan-activity; sid:100002025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.103.56"; classtype:trojan-activity; sid:100002026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.64.63"; classtype:trojan-activity; sid:100002027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.180.67"; classtype:trojan-activity; sid:100002028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.181.7"; classtype:trojan-activity; sid:100002029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.57.96.116"; classtype:trojan-activity; sid:100002030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.170.60"; classtype:trojan-activity; sid:100002031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.73.220"; classtype:trojan-activity; sid:100002032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.61.218.23"; classtype:trojan-activity; sid:100002033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.65.172.121"; classtype:trojan-activity; sid:100002034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.0.22"; classtype:trojan-activity; sid:100002035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.104.46"; classtype:trojan-activity; sid:100002036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.110.59"; classtype:trojan-activity; sid:100002037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.195"; classtype:trojan-activity; sid:100002038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.86"; classtype:trojan-activity; sid:100002039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.255.60"; classtype:trojan-activity; sid:100002040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.45.130"; classtype:trojan-activity; sid:100002041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.98.144.75"; classtype:trojan-activity; sid:100002042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.1.98.131"; classtype:trojan-activity; sid:100002043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.141.73.58"; classtype:trojan-activity; sid:100002044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.131.205"; classtype:trojan-activity; sid:100002045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.143.46"; classtype:trojan-activity; sid:100002046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.155.61"; classtype:trojan-activity; sid:100002047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.227.31"; classtype:trojan-activity; sid:100002048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.31.126.33"; classtype:trojan-activity; sid:100002049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.149.66"; classtype:trojan-activity; sid:100002050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.222.98"; classtype:trojan-activity; sid:100002051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.43.207.148"; classtype:trojan-activity; sid:100002052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.90.165.236"; classtype:trojan-activity; sid:100002053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"63.245.122.93"; classtype:trojan-activity; sid:100002054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"64.233.154.99"; classtype:trojan-activity; sid:100002055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.125.128.196"; classtype:trojan-activity; sid:100002056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.21.58.252"; classtype:trojan-activity; sid:100002057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.26.155.131"; classtype:trojan-activity; sid:100002058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.35.61.255"; classtype:trojan-activity; sid:100002059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.229.214.115"; classtype:trojan-activity; sid:100002060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.57.55.210"; classtype:trojan-activity; sid:100002061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.74.7.197"; classtype:trojan-activity; sid:100002062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.97.181.196"; classtype:trojan-activity; sid:100002063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.245.151.203"; classtype:trojan-activity; sid:100002064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.3.169.223"; classtype:trojan-activity; sid:100002065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.8.138.101"; classtype:trojan-activity; sid:100002066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.83.49.234"; classtype:trojan-activity; sid:100002067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.84.138.165"; classtype:trojan-activity; sid:100002068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.148.103.248"; classtype:trojan-activity; sid:100002069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.151.244.128"; classtype:trojan-activity; sid:100002070; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.174.182.226"; classtype:trojan-activity; sid:100002071; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.175.107.153"; classtype:trojan-activity; sid:100002072; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.188.144.143"; classtype:trojan-activity; sid:100002073; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.204.88.29"; classtype:trojan-activity; sid:100002074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.106.84"; classtype:trojan-activity; sid:100002075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.119.241"; classtype:trojan-activity; sid:100002076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.78.33.33"; classtype:trojan-activity; sid:100002077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.115.37.205"; classtype:trojan-activity; sid:100002078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.120.237.255"; classtype:trojan-activity; sid:100002079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.123.245.151"; classtype:trojan-activity; sid:100002080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.124.231.110"; classtype:trojan-activity; sid:100002081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.127.214.47"; classtype:trojan-activity; sid:100002082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.146.232.34"; classtype:trojan-activity; sid:100002083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.165.173.49"; classtype:trojan-activity; sid:100002084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.196.158.227"; classtype:trojan-activity; sid:100002085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.222.157.166"; classtype:trojan-activity; sid:100002086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.229.0.133"; classtype:trojan-activity; sid:100002087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.63.73.234"; classtype:trojan-activity; sid:100002088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.115.194"; classtype:trojan-activity; sid:100002089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.227.186"; classtype:trojan-activity; sid:100002090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.76.240.206"; classtype:trojan-activity; sid:100002091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.115.31.30"; classtype:trojan-activity; sid:100002092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.118.240.88"; classtype:trojan-activity; sid:100002093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.167.10.180"; classtype:trojan-activity; sid:100002094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.236.190.250"; classtype:trojan-activity; sid:100002095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.25.5.105"; classtype:trojan-activity; sid:100002096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.93.129.118"; classtype:trojan-activity; sid:100002097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.127.148.69"; classtype:trojan-activity; sid:100002098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.146.190.91"; classtype:trojan-activity; sid:100002099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.204.63.239"; classtype:trojan-activity; sid:100002100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.29.48.164"; classtype:trojan-activity; sid:100002101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.34.191.213"; classtype:trojan-activity; sid:100002102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.40.234.166"; classtype:trojan-activity; sid:100002103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.106.142"; classtype:trojan-activity; sid:100002104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.2.122"; classtype:trojan-activity; sid:100002105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.235.106"; classtype:trojan-activity; sid:100002106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.47.133.58"; classtype:trojan-activity; sid:100002107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.71.60.69"; classtype:trojan-activity; sid:100002108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.85.106.211"; classtype:trojan-activity; sid:100002109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.17.22.30"; classtype:trojan-activity; sid:100002110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.186.139.38"; classtype:trojan-activity; sid:100002111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.180.98"; classtype:trojan-activity; sid:100002112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.200.62"; classtype:trojan-activity; sid:100002113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.202.249.109"; classtype:trojan-activity; sid:100002114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.214.69.226"; classtype:trojan-activity; sid:100002115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.229.230.118"; classtype:trojan-activity; sid:100002116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.31.40.122"; classtype:trojan-activity; sid:100002117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.204.216.103"; classtype:trojan-activity; sid:100002118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.70.164.42"; classtype:trojan-activity; sid:100002119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.101.1.159"; classtype:trojan-activity; sid:100002120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.108.224.112"; classtype:trojan-activity; sid:100002121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.194.117.165"; classtype:trojan-activity; sid:100002122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.195.115.176"; classtype:trojan-activity; sid:100002123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.199.84.77"; classtype:trojan-activity; sid:100002124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.64.139.223"; classtype:trojan-activity; sid:100002125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.75.165.81"; classtype:trojan-activity; sid:100002126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.127.141.52"; classtype:trojan-activity; sid:100002127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.82.36.220"; classtype:trojan-activity; sid:100002128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.83.102.27"; classtype:trojan-activity; sid:100002129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.99.213.61"; classtype:trojan-activity; sid:100002130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.170.11.82"; classtype:trojan-activity; sid:100002131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.178.22.145"; classtype:trojan-activity; sid:100002132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.217.92.231"; classtype:trojan-activity; sid:100002133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.250.199.133"; classtype:trojan-activity; sid:100002134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.254.129.227"; classtype:trojan-activity; sid:100002135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.84.134.33"; classtype:trojan-activity; sid:100002136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.95.12.137"; classtype:trojan-activity; sid:100002137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.111.182.31"; classtype:trojan-activity; sid:100002138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.237.25.210"; classtype:trojan-activity; sid:100002139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.53.144.46"; classtype:trojan-activity; sid:100002140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.50.153"; classtype:trojan-activity; sid:100002141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.52.220"; classtype:trojan-activity; sid:100002142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.89.203.238"; classtype:trojan-activity; sid:100002143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77st.net"; classtype:trojan-activity; sid:100002144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.145.224.45"; classtype:trojan-activity; sid:100002145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.186.155.18"; classtype:trojan-activity; sid:100002146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.141.144"; classtype:trojan-activity; sid:100002147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.240.125"; classtype:trojan-activity; sid:100002148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.41.200"; classtype:trojan-activity; sid:100002149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.168.64"; classtype:trojan-activity; sid:100002150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.188.141"; classtype:trojan-activity; sid:100002151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.104.157"; classtype:trojan-activity; sid:100002152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.176.163"; classtype:trojan-activity; sid:100002153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.27.157"; classtype:trojan-activity; sid:100002154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.23.172.81"; classtype:trojan-activity; sid:100002155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.8.225.77"; classtype:trojan-activity; sid:100002156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.11.195.121"; classtype:trojan-activity; sid:100002157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.13.49.221"; classtype:trojan-activity; sid:100002158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.130.253.13"; classtype:trojan-activity; sid:100002159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.147.123.48"; classtype:trojan-activity; sid:100002160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.175.42.244"; classtype:trojan-activity; sid:100002161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.7.170.58"; classtype:trojan-activity; sid:100002162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.79.58.94"; classtype:trojan-activity; sid:100002163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.8.70.162"; classtype:trojan-activity; sid:100002164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.9.88.185"; classtype:trojan-activity; sid:100002165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.107.89.207"; classtype:trojan-activity; sid:100002166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.19.101.218"; classtype:trojan-activity; sid:100002167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.211.181.77"; classtype:trojan-activity; sid:100002168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.217.12.7"; classtype:trojan-activity; sid:100002169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.99.128.61"; classtype:trojan-activity; sid:100002170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.136.146.213"; classtype:trojan-activity; sid:100002171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.165.44.109"; classtype:trojan-activity; sid:100002172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.191.40.58"; classtype:trojan-activity; sid:100002173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.213.141.184"; classtype:trojan-activity; sid:100002174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.187.113"; classtype:trojan-activity; sid:100002175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.195.216"; classtype:trojan-activity; sid:100002176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.237.128.200"; classtype:trojan-activity; sid:100002177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.244.219.41"; classtype:trojan-activity; sid:100002178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.246.225.203"; classtype:trojan-activity; sid:100002179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.92.36.96"; classtype:trojan-activity; sid:100002180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.103.108.72"; classtype:trojan-activity; sid:100002181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.135.196.130"; classtype:trojan-activity; sid:100002182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.212.178"; classtype:trojan-activity; sid:100002183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.85.112"; classtype:trojan-activity; sid:100002184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.207.61.194"; classtype:trojan-activity; sid:100002185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.209.250.155"; classtype:trojan-activity; sid:100002186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.211.156.38"; classtype:trojan-activity; sid:100002187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.59.31.181"; classtype:trojan-activity; sid:100002188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.110.252"; classtype:trojan-activity; sid:100002189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.53.77"; classtype:trojan-activity; sid:100002190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.138.72"; classtype:trojan-activity; sid:100002191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.139.92"; classtype:trojan-activity; sid:100002192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.154.214"; classtype:trojan-activity; sid:100002193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.187.109"; classtype:trojan-activity; sid:100002194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.100.54"; classtype:trojan-activity; sid:100002195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.106.65"; classtype:trojan-activity; sid:100002196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.108.172"; classtype:trojan-activity; sid:100002197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.131.158"; classtype:trojan-activity; sid:100002198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.19.42"; classtype:trojan-activity; sid:100002199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.197.254"; classtype:trojan-activity; sid:100002200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.215.149"; classtype:trojan-activity; sid:100002201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.232.68"; classtype:trojan-activity; sid:100002202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.234.195"; classtype:trojan-activity; sid:100002203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.246.96"; classtype:trojan-activity; sid:100002204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.28.57"; classtype:trojan-activity; sid:100002205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.4.57"; classtype:trojan-activity; sid:100002206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.55.84"; classtype:trojan-activity; sid:100002207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.73.245"; classtype:trojan-activity; sid:100002208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.98.51"; classtype:trojan-activity; sid:100002209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.165.237.163"; classtype:trojan-activity; sid:100002210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.147.99"; classtype:trojan-activity; sid:100002211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.218.42"; classtype:trojan-activity; sid:100002212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.242.253.154"; classtype:trojan-activity; sid:100002213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.252.9.37"; classtype:trojan-activity; sid:100002214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.210.219.213"; classtype:trojan-activity; sid:100002215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.212.219.127"; classtype:trojan-activity; sid:100002216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.50.118"; classtype:trojan-activity; sid:100002217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.95.204"; classtype:trojan-activity; sid:100002218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.238.24.35"; classtype:trojan-activity; sid:100002219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.247.83.74"; classtype:trojan-activity; sid:100002220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.254.39.129"; classtype:trojan-activity; sid:100002221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.33.111.227"; classtype:trojan-activity; sid:100002222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.39.248.2"; classtype:trojan-activity; sid:100002223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.40.127.242"; classtype:trojan-activity; sid:100002224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.42.20.217"; classtype:trojan-activity; sid:100002225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; classtype:trojan-activity; sid:100002226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.11.216"; classtype:trojan-activity; sid:100002227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.123.251"; classtype:trojan-activity; sid:100002228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.135.187"; classtype:trojan-activity; sid:100002229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.180.33"; classtype:trojan-activity; sid:100002230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.224.141"; classtype:trojan-activity; sid:100002231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.241.2"; classtype:trojan-activity; sid:100002232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.214.149.236"; classtype:trojan-activity; sid:100002233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.64.181.50"; classtype:trojan-activity; sid:100002234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.64.203.204"; classtype:trojan-activity; sid:100002235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.74.215.180"; classtype:trojan-activity; sid:100002236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.130.227"; classtype:trojan-activity; sid:100002237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.195.129"; classtype:trojan-activity; sid:100002238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"86.35.43.220"; classtype:trojan-activity; sid:100002239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.172.19.130"; classtype:trojan-activity; sid:100002240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.61.89.40"; classtype:trojan-activity; sid:100002241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87du.vip"; classtype:trojan-activity; sid:100002242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.208.71"; classtype:trojan-activity; sid:100002243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.219.179"; classtype:trojan-activity; sid:100002244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.225.222.128"; classtype:trojan-activity; sid:100002245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.247.96.19"; classtype:trojan-activity; sid:100002246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.136.231"; classtype:trojan-activity; sid:100002247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.51.139"; classtype:trojan-activity; sid:100002248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.249.244.180"; classtype:trojan-activity; sid:100002249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.204.12"; classtype:trojan-activity; sid:100002250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.226.26"; classtype:trojan-activity; sid:100002251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.240.245"; classtype:trojan-activity; sid:100002252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.254.90"; classtype:trojan-activity; sid:100002253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.122.183.130"; classtype:trojan-activity; sid:100002254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.136.197.170"; classtype:trojan-activity; sid:100002255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.22.152.244"; classtype:trojan-activity; sid:100002256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.29.213.33"; classtype:trojan-activity; sid:100002257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.85.166"; classtype:trojan-activity; sid:100002258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8poieq.bn.files.1drv.com"; classtype:trojan-activity; sid:100002259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"90.152.144.139"; classtype:trojan-activity; sid:100002260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.132.197.39"; classtype:trojan-activity; sid:100002261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.138.215.5"; classtype:trojan-activity; sid:100002262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.177.139.132"; classtype:trojan-activity; sid:100002263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.187.103.32"; classtype:trojan-activity; sid:100002264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.205.173.252"; classtype:trojan-activity; sid:100002265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.212.150.241"; classtype:trojan-activity; sid:100002266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.214.124.141"; classtype:trojan-activity; sid:100002267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.217.104.185"; classtype:trojan-activity; sid:100002268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.233.112.188"; classtype:trojan-activity; sid:100002269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.239.168.83"; classtype:trojan-activity; sid:100002270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.92.16.244"; classtype:trojan-activity; sid:100002271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.98.4.181"; classtype:trojan-activity; sid:100002272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.114.191.82"; classtype:trojan-activity; sid:100002273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.241.78.114"; classtype:trojan-activity; sid:100002274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.27.246.202"; classtype:trojan-activity; sid:100002275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.83.62.139"; classtype:trojan-activity; sid:100002276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.85.18.138"; classtype:trojan-activity; sid:100002277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.159.169.190"; classtype:trojan-activity; sid:100002278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.21.224.154"; classtype:trojan-activity; sid:100002279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.39.115.176"; classtype:trojan-activity; sid:100002280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.39.79.41"; classtype:trojan-activity; sid:100002281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.137.16"; classtype:trojan-activity; sid:100002282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.182.249"; classtype:trojan-activity; sid:100002283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.206.56"; classtype:trojan-activity; sid:100002284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.57.43.233"; classtype:trojan-activity; sid:100002285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.73.99.102"; classtype:trojan-activity; sid:100002286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.136.69.199"; classtype:trojan-activity; sid:100002287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.143.53.34"; classtype:trojan-activity; sid:100002288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.154.17.170"; classtype:trojan-activity; sid:100002289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.200.16.22"; classtype:trojan-activity; sid:100002290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.224.83.208"; classtype:trojan-activity; sid:100002291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.53.120.109"; classtype:trojan-activity; sid:100002292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.85.0.3"; classtype:trojan-activity; sid:100002293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.132.129.250"; classtype:trojan-activity; sid:100002294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.154.20.231"; classtype:trojan-activity; sid:100002295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.158.19.130"; classtype:trojan-activity; sid:100002296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.113.227"; classtype:trojan-activity; sid:100002297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.113.52"; classtype:trojan-activity; sid:100002298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.201.34"; classtype:trojan-activity; sid:100002299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.60.146.134"; classtype:trojan-activity; sid:100002300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.66.196.63"; classtype:trojan-activity; sid:100002301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.9.120.40"; classtype:trojan-activity; sid:100002302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.9.81.85"; classtype:trojan-activity; sid:100002303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.239.73.246"; classtype:trojan-activity; sid:100002304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.47.147.169"; classtype:trojan-activity; sid:100002305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.68.140.254"; classtype:trojan-activity; sid:100002306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.96.199.75"; classtype:trojan-activity; sid:100002307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.0.210.218"; classtype:trojan-activity; sid:100002308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.113.239.207"; classtype:trojan-activity; sid:100002309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.116.72.119"; classtype:trojan-activity; sid:100002310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.128.147.115"; classtype:trojan-activity; sid:100002311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.178.242.44"; classtype:trojan-activity; sid:100002312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.30.24.54"; classtype:trojan-activity; sid:100002313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.150.245.203"; classtype:trojan-activity; sid:100002314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.33.195.164"; classtype:trojan-activity; sid:100002315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aatreefelling.co.za"; classtype:trojan-activity; sid:100002316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abad.tv"; classtype:trojan-activity; sid:100002317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abcd.bg"; classtype:trojan-activity; sid:100002318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abissnet.net"; classtype:trojan-activity; sid:100002319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aboveandbelow.com.au"; classtype:trojan-activity; sid:100002320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absoftechworld.com"; classtype:trojan-activity; sid:100002321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absupplies.co.uk"; classtype:trojan-activity; sid:100002322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abyssos.eu"; classtype:trojan-activity; sid:100002323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"academyshademani.com"; classtype:trojan-activity; sid:100002324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acbick.com"; classtype:trojan-activity; sid:100002325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"accesslinksgroup.com"; classtype:trojan-activity; sid:100002326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aceeprc.com.aceeprc.com"; classtype:trojan-activity; sid:100002327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acellr.co.uk"; classtype:trojan-activity; sid:100002328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acteon.com.ar"; classtype:trojan-activity; sid:100002329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"activecost.com.au"; classtype:trojan-activity; sid:100002330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"addahealingmusic.com"; classtype:trojan-activity; sid:100002331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.com"; classtype:trojan-activity; sid:100002332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.memengers.com"; classtype:trojan-activity; sid:100002333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.erapor.smk-alasror.net"; classtype:trojan-activity; sid:100002334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.gentbcn.org"; classtype:trojan-activity; sid:100002335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.grandoceanvilla.com"; classtype:trojan-activity; sid:100002336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admission.kmctartskuttippuram.org"; classtype:trojan-activity; sid:100002337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adventureexplorer.in"; classtype:trojan-activity; sid:100002338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aeropilates.cl"; classtype:trojan-activity; sid:100002339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afnan-amc.com"; classtype:trojan-activity; sid:100002340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afoninblog.com"; classtype:trojan-activity; sid:100002341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afrimedspecialist.com"; classtype:trojan-activity; sid:100002342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agemn.co.za"; classtype:trojan-activity; sid:100002343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenciadigitalwdys.com"; classtype:trojan-activity; sid:100002344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenda.gmelloinformatica.com.br"; classtype:trojan-activity; sid:100002345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agentt.ac.ug"; classtype:trojan-activity; sid:100002346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agile8studio.com"; classtype:trojan-activity; sid:100002347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aiecons.com"; classtype:trojan-activity; sid:100002348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aimnaukri.com"; classtype:trojan-activity; sid:100002349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aiqtest.com"; classtype:trojan-activity; sid:100002350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aitorocio.com"; classtype:trojan-activity; sid:100002351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajpharmaholding.com"; classtype:trojan-activity; sid:100002352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajstudiollc.com"; classtype:trojan-activity; sid:100002353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"akdvidyalaya.com"; classtype:trojan-activity; sid:100002354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"al-wahd.com"; classtype:trojan-activity; sid:100002355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alasdemariposas.org"; classtype:trojan-activity; sid:100002356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alberts.diamondrelationscrm.us"; classtype:trojan-activity; sid:100002357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alemelektronik.com"; classtype:trojan-activity; sid:100002358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alena1971.es"; classtype:trojan-activity; sid:100002359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alexdubai.com.aldiabsteel.com"; classtype:trojan-activity; sid:100002360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alka.institute"; classtype:trojan-activity; sid:100002361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"allforcreative.com.au"; classtype:trojan-activity; sid:100002362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alltheway.travel"; classtype:trojan-activity; sid:100002363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alpaylar.com.tr"; classtype:trojan-activity; sid:100002364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"am-concepts.ca"; classtype:trojan-activity; sid:100002365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amamontajes.com"; classtype:trojan-activity; sid:100002366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarresdeamorymaestroshechiceros.com"; classtype:trojan-activity; sid:100002367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarteargentina.com.ar"; classtype:trojan-activity; sid:100002368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amos524.org"; classtype:trojan-activity; sid:100002369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ams.alvinasschools.org.ng"; classtype:trojan-activity; sid:100002370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anadelgbt.org"; classtype:trojan-activity; sid:100002371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anantam.net.in"; classtype:trojan-activity; sid:100002372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreelapeyre.com"; classtype:trojan-activity; sid:100002373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andremaraisbeleggings.co.za"; classtype:trojan-activity; sid:100002374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ac.ug"; classtype:trojan-activity; sid:100002375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ug"; classtype:trojan-activity; sid:100002376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreshconcejal.solucioneslink.com"; classtype:trojan-activity; sid:100002377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelazgheibld.com"; classtype:trojan-activity; sid:100002378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelsdetour.com"; classtype:trojan-activity; sid:100002379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angloteste.bigprime.com.br"; classtype:trojan-activity; sid:100002380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anhung1102.vn"; classtype:trojan-activity; sid:100002381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anurontv.com"; classtype:trojan-activity; sid:100002382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anysbergbiltong.co.za"; classtype:trojan-activity; sid:100002383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apartamentoscitta.com"; classtype:trojan-activity; sid:100002384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api-ms.cobainaja.id"; classtype:trojan-activity; sid:100002385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.cstdevs.com"; classtype:trojan-activity; sid:100002386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.quocbao.biz"; classtype:trojan-activity; sid:100002387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apoolcondo.com"; classtype:trojan-activity; sid:100002388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.adsensearticle.com"; classtype:trojan-activity; sid:100002389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.explicitsurveys.co.uk"; classtype:trojan-activity; sid:100002390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.prerana.info"; classtype:trojan-activity; sid:100002391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apps.saintsoporte.com"; classtype:trojan-activity; sid:100002392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aps-scribe.com"; classtype:trojan-activity; sid:100002393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aps-sv.com"; classtype:trojan-activity; sid:100002394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apsusa.aero"; classtype:trojan-activity; sid:100002395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"areyoulivingwell.com"; classtype:trojan-activity; sid:100002396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"artedibujoyarquitectura.com"; classtype:trojan-activity; sid:100002397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"arwenyapi.com"; classtype:trojan-activity; sid:100002398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ask-regard.call-save.biz"; classtype:trojan-activity; sid:100002399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atfile.com"; classtype:trojan-activity; sid:100002400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"athenacapsg.com"; classtype:trojan-activity; sid:100002401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atlanticsteelprocessing.com"; classtype:trojan-activity; sid:100002402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atlasconcreteworks.com"; classtype:trojan-activity; sid:100002403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"attach.66rpg.com"; classtype:trojan-activity; sid:100002404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atteuqpotentialunlimited.com"; classtype:trojan-activity; sid:100002405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"augustair.com"; classtype:trojan-activity; sid:100002406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"avadhanagames.com"; classtype:trojan-activity; sid:100002407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ayahuascasp.com.br"; classtype:trojan-activity; sid:100002408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ayamallah.com"; classtype:trojan-activity; sid:100002409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azmeasurement.com"; classtype:trojan-activity; sid:100002410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"b2b.toptanakaryakit.com.tr"; classtype:trojan-activity; sid:100002411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"backgrounds.pk"; classtype:trojan-activity; sid:100002412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"badeggdesign.com"; classtype:trojan-activity; sid:100002413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"balealgodon.mx"; classtype:trojan-activity; sid:100002414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ballina.andrewmaughan.com"; classtype:trojan-activity; sid:100002415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bangkok-orchids.com"; classtype:trojan-activity; sid:100002416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bangladeshunbound.com"; classtype:trojan-activity; sid:100002417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bary.sz4h.com"; classtype:trojan-activity; sid:100002418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bash.givemexyz.in"; classtype:trojan-activity; sid:100002419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; classtype:trojan-activity; sid:100002420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bavhome.com"; classtype:trojan-activity; sid:100002421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bbia.co.uk"; classtype:trojan-activity; sid:100002422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcmt.elin.co.za"; classtype:trojan-activity; sid:100002423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcrg.co.za"; classtype:trojan-activity; sid:100002424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bdnextrend.xyz"; classtype:trojan-activity; sid:100002425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bearcatpumps.com.cn"; classtype:trojan-activity; sid:100002426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beautincollagen.rs"; classtype:trojan-activity; sid:100002427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bekape.co.id"; classtype:trojan-activity; sid:100002428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beor360.com"; classtype:trojan-activity; sid:100002429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bespokeweddings.ie"; classtype:trojan-activity; sid:100002430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bestcarenepal.com"; classtype:trojan-activity; sid:100002431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betone.co.kr"; classtype:trojan-activity; sid:100002432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beveragesmiami.solucioneslink.com"; classtype:trojan-activity; sid:100002433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bhavaniengineering.com"; classtype:trojan-activity; sid:100002434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bigmikesupplies.co.za"; classtype:trojan-activity; sid:100002435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilbosaquet.ug"; classtype:trojan-activity; sid:100002436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilhen.co.za"; classtype:trojan-activity; sid:100002437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"billing.citywine.in"; classtype:trojan-activity; sid:100002438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"billing.rahitechnosoft.com"; classtype:trojan-activity; sid:100002439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"binoy.stalphonsamissionva.org"; classtype:trojan-activity; sid:100002440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"biometrico.gpotecnosystems.com"; classtype:trojan-activity; sid:100002441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bioskey.com"; classtype:trojan-activity; sid:100002442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birdi.elin.co.za"; classtype:trojan-activity; sid:100002443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birminghamlink.org"; classtype:trojan-activity; sid:100002444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bizztradingbot.nl"; classtype:trojan-activity; sid:100002445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bl4n3.zadns.co.za"; classtype:trojan-activity; sid:100002446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.callensaxen.com"; classtype:trojan-activity; sid:100002447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.cast.re"; classtype:trojan-activity; sid:100002448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.difusodesign.com"; classtype:trojan-activity; sid:100002449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.oyinblogs.com"; classtype:trojan-activity; sid:100002450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.takbelit.com"; classtype:trojan-activity; sid:100002451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bmlifestyle.co.uk"; classtype:trojan-activity; sid:100002452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bnrnews.id"; classtype:trojan-activity; sid:100002453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"boatpecas.com.br"; classtype:trojan-activity; sid:100002454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bodenstein.co.za"; classtype:trojan-activity; sid:100002455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"booksearch.com"; classtype:trojan-activity; sid:100002456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bophelocare.co.za"; classtype:trojan-activity; sid:100002457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bounces.mi-fs.com"; classtype:trojan-activity; sid:100002458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"boutiqueofferte.com"; classtype:trojan-activity; sid:100002459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bpo.correct.go.th"; classtype:trojan-activity; sid:100002460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brandtrust.com.pk"; classtype:trojan-activity; sid:100002461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"braunfinancial.com.au"; classtype:trojan-activity; sid:100002462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brendanquine.com"; classtype:trojan-activity; sid:100002463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brideofmessiah.com"; classtype:trojan-activity; sid:100002464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightaffiliatesales.org"; classtype:trojan-activity; sid:100002465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightmega.com"; classtype:trojan-activity; sid:100002466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightstarshop.com"; classtype:trojan-activity; sid:100002467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"browardinsurancemiami.solucioneslink.com"; classtype:trojan-activity; sid:100002468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bt2.elin.co.za"; classtype:trojan-activity; sid:100002469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"btdapi.robotake.com"; classtype:trojan-activity; sid:100002470; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buigiaphat.com.vn"; classtype:trojan-activity; sid:100002471; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bulkyfoodja.com"; classtype:trojan-activity; sid:100002472; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bullseyemedia.in"; classtype:trojan-activity; sid:100002473; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"busandvanrentalmalaysia.com"; classtype:trojan-activity; sid:100002474; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buscascolegios.diit.cl"; classtype:trojan-activity; sid:100002475; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"business.softberg.ro"; classtype:trojan-activity; sid:100002476; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"business2.softberg.ro"; classtype:trojan-activity; sid:100002477; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bydspa.cl"; classtype:trojan-activity; sid:100002478; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c.oooooooooo.ga"; classtype:trojan-activity; sid:100002479; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c0140529.ferozo.com"; classtype:trojan-activity; sid:100002480; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"caballo.com.au"; classtype:trojan-activity; sid:100002481; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cacaoprojects.com"; classtype:trojan-activity; sid:100002482; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"calgaryautorepairservice.com"; classtype:trojan-activity; sid:100002483; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"callbury.in"; classtype:trojan-activity; sid:100002484; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"camminachetipassa.it"; classtype:trojan-activity; sid:100002485; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"canadianwork.cc"; classtype:trojan-activity; sid:100002486; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capitalgroup-kw.com"; classtype:trojan-activity; sid:100002487; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capoeiraventrelivre.com"; classtype:trojan-activity; sid:100002488; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cardilicores.com"; classtype:trojan-activity; sid:100002489; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cashyinvestment.org"; classtype:trojan-activity; sid:100002490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"catchperch.com"; classtype:trojan-activity; sid:100002491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"catchpoolshetlands.co.uk"; classtype:trojan-activity; sid:100002492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cazyacustomfurniture.com"; classtype:trojan-activity; sid:100002493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cbn.hypervoizd.com"; classtype:trojan-activity; sid:100002494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ccauthority.net"; classtype:trojan-activity; sid:100002495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cdaonline.com.ar"; classtype:trojan-activity; sid:100002496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cec.asso.ac-amiens.fr"; classtype:trojan-activity; sid:100002497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cecra.cl"; classtype:trojan-activity; sid:100002498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cellas.sk"; classtype:trojan-activity; sid:100002499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cendekiabinaaksara.com"; classtype:trojan-activity; sid:100002500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cfs5.tistory.com"; classtype:trojan-activity; sid:100002501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ch.rmu.ac.th"; classtype:trojan-activity; sid:100002502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chance5.xyz"; classtype:trojan-activity; sid:100002503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"changematterscounselling.com"; classtype:trojan-activity; sid:100002504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chardhamdodham.com"; classtype:trojan-activity; sid:100002505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"check.askwordpressguru.com"; classtype:trojan-activity; sid:100002506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chezalice.co.za"; classtype:trojan-activity; sid:100002507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"childselect.com"; classtype:trojan-activity; sid:100002508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile.myvnc.com"; classtype:trojan-activity; sid:100002509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile80.myvnc.com"; classtype:trojan-activity; sid:100002510; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cible-energy.com"; classtype:trojan-activity; sid:100002511; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cifeer.net"; classtype:trojan-activity; sid:100002512; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cirugiadenarizbucaramanga.com"; classtype:trojan-activity; sid:100002513; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citihits.lk"; classtype:trojan-activity; sid:100002514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citssolutions.co.za"; classtype:trojan-activity; sid:100002515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citycapproperty.ru"; classtype:trojan-activity; sid:100002516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cityglobalgospel.com"; classtype:trojan-activity; sid:100002517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"civi.istmejia.com"; classtype:trojan-activity; sid:100002518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cleanbydesignllc.com"; classtype:trojan-activity; sid:100002519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cloud.fc.co.mz"; classtype:trojan-activity; sid:100002520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cm-arquitetos.com"; classtype:trojan-activity; sid:100002521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"codsambal.com"; classtype:trojan-activity; sid:100002522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colempaques.info"; classtype:trojan-activity; sid:100002523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colinde.pricesne.com"; classtype:trojan-activity; sid:100002524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colorpak.pl"; classtype:trojan-activity; sid:100002525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"community.reimclub.com"; classtype:trojan-activity; sid:100002526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"comosairdoburaco.com.br"; classtype:trojan-activity; sid:100002527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"competancy.indigoconsult.net"; classtype:trojan-activity; sid:100002528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"conceptimagine.ro"; classtype:trojan-activity; sid:100002529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"config.cqhbkjzx.com"; classtype:trojan-activity; sid:100002530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"connectcapital.com.br"; classtype:trojan-activity; sid:100002531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"constructoralyon.com"; classtype:trojan-activity; sid:100002532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"consulateins.solucioneslink.com"; classtype:trojan-activity; sid:100002533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"contributeindustry.com"; classtype:trojan-activity; sid:100002534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"controleautomacao.com.br"; classtype:trojan-activity; sid:100002535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"copelandscapes.com"; classtype:trojan-activity; sid:100002536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"coulsongraphics.com"; classtype:trojan-activity; sid:100002537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"count.mail.163.com.impactmedfoundation.com"; classtype:trojan-activity; sid:100002538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"covid19.cyberschool.or.id"; classtype:trojan-activity; sid:100002539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cpanel.shivay.net"; classtype:trojan-activity; sid:100002540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cr-sq.com"; classtype:trojan-activity; sid:100002541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"craftech.nxtnet.ga"; classtype:trojan-activity; sid:100002542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crearechile.cl"; classtype:trojan-activity; sid:100002543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"creationskateboards.com"; classtype:trojan-activity; sid:100002544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crecerco.com"; classtype:trojan-activity; sid:100002545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crittersbythebay.com"; classtype:trojan-activity; sid:100002546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crm.notariavieitoyvelamazan.com"; classtype:trojan-activity; sid:100002547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crmfarko.manivelasst.com"; classtype:trojan-activity; sid:100002548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crmroche.manivelasst.com"; classtype:trojan-activity; sid:100002549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crscorretordeimoveis.com.br"; classtype:trojan-activity; sid:100002550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cse-engineer.com"; classtype:trojan-activity; sid:100002551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"csnserver.com"; classtype:trojan-activity; sid:100002552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ctracknxt.in"; classtype:trojan-activity; sid:100002553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cubescargoexpress.com"; classtype:trojan-activity; sid:100002554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"curasoles.co.za"; classtype:trojan-activity; sid:100002555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"currantmedia.com"; classtype:trojan-activity; sid:100002556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cwa.mx"; classtype:trojan-activity; sid:100002557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cyclomove.com"; classtype:trojan-activity; sid:100002558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cynkon.kairoscs.net"; classtype:trojan-activity; sid:100002559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"czsl.91756.cn"; classtype:trojan-activity; sid:100002560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d.powerofwish.com"; classtype:trojan-activity; sid:100002561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d9.99ddd.com"; classtype:trojan-activity; sid:100002562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"da.alibuf.com"; classtype:trojan-activity; sid:100002563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dagiionline.com"; classtype:trojan-activity; sid:100002564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"damagedessentialtelecommunications.testmail4.repl.co"; classtype:trojan-activity; sid:100002565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"danaevara.com"; classtype:trojan-activity; sid:100002566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dartoonpictures.com"; classtype:trojan-activity; sid:100002567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.cdevelop.org"; classtype:trojan-activity; sid:100002568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.over-blog-kiwi.com"; classtype:trojan-activity; sid:100002569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datapolish.com"; classtype:trojan-activity; sid:100002570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dating.khokhas.co.za"; classtype:trojan-activity; sid:100002571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datsom.vn"; classtype:trojan-activity; sid:100002572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davethompson.me.uk"; classtype:trojan-activity; sid:100002573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davidmcguinness.info"; classtype:trojan-activity; sid:100002574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dayspringdaisies.com"; classtype:trojan-activity; sid:100002575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dd.qiyuea.cn"; classtype:trojan-activity; sid:100002576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"de.gsearch.com.de"; classtype:trojan-activity; sid:100002577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"decifrar.com.br"; classtype:trojan-activity; sid:100002578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"deigratia2.elin.co.za"; classtype:trojan-activity; sid:100002579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dekovizyon.com"; classtype:trojan-activity; sid:100002580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo-cliente.mindcreative.com.br"; classtype:trojan-activity; sid:100002581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo.glassforcars.com.au"; classtype:trojan-activity; sid:100002582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo.iiitindia.in"; classtype:trojan-activity; sid:100002583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo6.hiites.com"; classtype:trojan-activity; sid:100002584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dent-estet.com"; classtype:trojan-activity; sid:100002585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dental.xiaoxiao.media"; classtype:trojan-activity; sid:100002586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dentalalliance.se"; classtype:trojan-activity; sid:100002587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"desertlandtrd.com"; classtype:trojan-activity; sid:100002588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"designerliving.co.za"; classtype:trojan-activity; sid:100002589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"desiringhands.com"; classtype:trojan-activity; sid:100002590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"despertaresi.com.br"; classtype:trojan-activity; sid:100002591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"destinymc.co.za"; classtype:trojan-activity; sid:100002592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"detorre.es"; classtype:trojan-activity; sid:100002593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev.sebpo.net"; classtype:trojan-activity; sid:100002594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev.watch-store.eu"; classtype:trojan-activity; sid:100002595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dezcom.com"; classtype:trojan-activity; sid:100002596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dfcf.91756.cn"; classtype:trojan-activity; sid:100002597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dfsfcsfcdsfsdvcfsvcscv.com"; classtype:trojan-activity; sid:100002598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"diamantenegro.mi-fs.com"; classtype:trojan-activity; sid:100002599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dienmayminhhung.com"; classtype:trojan-activity; sid:100002600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"digilib.dianhusada.ac.id"; classtype:trojan-activity; sid:100002601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"digisails.org"; classtype:trojan-activity; sid:100002602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"disinfection-cleaning.co.za"; classtype:trojan-activity; sid:100002603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"djking.f3322.net"; classtype:trojan-activity; sid:100002604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.1003b.56a.com"; classtype:trojan-activity; sid:100002605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.198424.com"; classtype:trojan-activity; sid:100002606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.installcdn-aws.com"; classtype:trojan-activity; sid:100002607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.packetstormsecurity.net"; classtype:trojan-activity; sid:100002608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.rina-roleplay.com"; classtype:trojan-activity; sid:100002609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dnn.alibuf.com"; classtype:trojan-activity; sid:100002610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dns.cyberium.cc"; classtype:trojan-activity; sid:100002611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dockerupdate.anondns.net"; classtype:trojan-activity; sid:100002612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"docman.orientalservices.in"; classtype:trojan-activity; sid:100002613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dodsonimaging.com"; classtype:trojan-activity; sid:100002614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"doitunlimited.com"; classtype:trojan-activity; sid:100002615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dokan.blueberrytec.com"; classtype:trojan-activity; sid:100002616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom-chel74.ru"; classtype:trojan-activity; sid:100002617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom.daf.free.fr"; classtype:trojan-activity; sid:100002618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"doncedyhall.com"; classtype:trojan-activity; sid:100002619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"donghobinhminh.com"; classtype:trojan-activity; sid:100002620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dongphuctop.com"; classtype:trojan-activity; sid:100002621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"donwnloasecury.ath.cx"; classtype:trojan-activity; sid:100002622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosame.com"; classtype:trojan-activity; sid:100002623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosman.pl"; classtype:trojan-activity; sid:100002624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dovberger.com"; classtype:trojan-activity; sid:100002625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.pcclear.com"; classtype:trojan-activity; sid:100002626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.udashi.com"; classtype:trojan-activity; sid:100002627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.webbora.com"; classtype:trojan-activity; sid:100002628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down1.arpun.com"; classtype:trojan-activity; sid:100002629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.caihong.com"; classtype:trojan-activity; sid:100002630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.doumaibiji.cn"; classtype:trojan-activity; sid:100002631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.exrnybuf.cn"; classtype:trojan-activity; sid:100002632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.kaobeitu.com"; classtype:trojan-activity; sid:100002633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.pdf00.cn"; classtype:trojan-activity; sid:100002634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.rising.com.cn"; classtype:trojan-activity; sid:100002635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.skycn.com"; classtype:trojan-activity; sid:100002636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.zjsyawqj.cn"; classtype:trojan-activity; sid:100002637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dragonsknot.com"; classtype:trojan-activity; sid:100002638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drbaby.com.sa"; classtype:trojan-activity; sid:100002639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dream.pics"; classtype:trojan-activity; sid:100002640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drgroup.co.za"; classtype:trojan-activity; sid:100002641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drools-moved.46999.n3.nabble.com"; classtype:trojan-activity; sid:100002642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drsha.innovativesolutions.mobi"; classtype:trojan-activity; sid:100002643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsdisplay.co.uk"; classtype:trojan-activity; sid:100002644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsenterprize.co.za"; classtype:trojan-activity; sid:100002645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsspainting.com"; classtype:trojan-activity; sid:100002646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"du-wizards.com"; classtype:trojan-activity; sid:100002647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duanhaozhang.com"; classtype:trojan-activity; sid:100002648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duque.guantanameratravel.com"; classtype:trojan-activity; sid:100002649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dutapp.wisolve.co.za"; classtype:trojan-activity; sid:100002650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duvalcharter.dekitout.com"; classtype:trojan-activity; sid:100002651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dx.qqyewu.com"; classtype:trojan-activity; sid:100002652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dzinestudio87.co.uk"; classtype:trojan-activity; sid:100002653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e-commerce.saleensuporte.com.br"; classtype:trojan-activity; sid:100002654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e.sldov.ru"; classtype:trojan-activity; sid:100002655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eandgdesign.com.ng"; classtype:trojan-activity; sid:100002656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eastsheen-glaziers.co.uk"; classtype:trojan-activity; sid:100002657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ebruyatkin.com"; classtype:trojan-activity; sid:100002658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"edu.saicraftsman.com"; classtype:trojan-activity; sid:100002659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eedo.ee"; classtype:trojan-activity; sid:100002660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"efficientegroup.com"; classtype:trojan-activity; sid:100002661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"elbauldenora.com"; classtype:trojan-activity; sid:100002662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"emaids.co.za"; classtype:trojan-activity; sid:100002663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"emaz.pk"; classtype:trojan-activity; sid:100002664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"emlak.ygtsoft.com"; classtype:trojan-activity; sid:100002665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"en.baoend.com"; classtype:trojan-activity; sid:100002666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enc-tech.com"; classtype:trojan-activity; sid:100002667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"endurotanzania.co.tz"; classtype:trojan-activity; sid:100002668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ennovate.elin.co.za"; classtype:trojan-activity; sid:100002669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enriquecendocomconsorcio.com.br"; classtype:trojan-activity; sid:100002670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"equimination.ee"; classtype:trojan-activity; sid:100002671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"erp.nanotechproautocare.com"; classtype:trojan-activity; sid:100002672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"erp.zilymax.com"; classtype:trojan-activity; sid:100002673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"escola.probommar.org.br"; classtype:trojan-activity; sid:100002674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"esnconsultants.com"; classtype:trojan-activity; sid:100002675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"essentia.org.br"; classtype:trojan-activity; sid:100002676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eubanks7.com"; classtype:trojan-activity; sid:100002677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"europeanzonexxi.com"; classtype:trojan-activity; sid:100002678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"evidencemarketing.ca"; classtype:trojan-activity; sid:100002679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exilum.com"; classtype:trojan-activity; sid:100002680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exitoalfaomega.co"; classtype:trojan-activity; sid:100002681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"extrovertoffers.com"; classtype:trojan-activity; sid:100002682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"f1sol.com"; classtype:trojan-activity; sid:100002683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fahrzeugdrive.com"; classtype:trojan-activity; sid:100002684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"familydentist.site"; classtype:trojan-activity; sid:100002685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"faveraprojects.com"; classtype:trojan-activity; sid:100002686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fc.co.mz"; classtype:trojan-activity; sid:100002687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"felicienne.nl"; classtype:trojan-activity; sid:100002688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"files.martellexpress.us"; classtype:trojan-activity; sid:100002689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"filmotainment.com"; classtype:trojan-activity; sid:100002690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"final.makkahkmcc.com"; classtype:trojan-activity; sid:100002691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fineartgallerym.com"; classtype:trojan-activity; sid:100002692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fisconline.casa"; classtype:trojan-activity; sid:100002693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fix-america-now.org"; classtype:trojan-activity; sid:100002694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fixauto.illumetechnology.com"; classtype:trojan-activity; sid:100002695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fixturegovernment.com"; classtype:trojan-activity; sid:100002696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fkd.derpcity.ru"; classtype:trojan-activity; sid:100002697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flexypay.dsquaregroup.com"; classtype:trojan-activity; sid:100002698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flintspin.com"; classtype:trojan-activity; sid:100002699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flyingbuddhadesign.com"; classtype:trojan-activity; sid:100002700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fmjplastering.co.uk"; classtype:trojan-activity; sid:100002701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fms.buladde.or.ug"; classtype:trojan-activity; sid:100002702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"follower.instantcashback.in"; classtype:trojan-activity; sid:100002703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foothills.com.br"; classtype:trojan-activity; sid:100002704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"footweardirect.elin.co.za"; classtype:trojan-activity; sid:100002705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"forum.mdb.nu"; classtype:trojan-activity; sid:100002706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fotoobjetivo.com"; classtype:trojan-activity; sid:100002707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foundationrepairhoustontx.net"; classtype:trojan-activity; sid:100002708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foxeps.com.br"; classtype:trojan-activity; sid:100002709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fraud.bpcbankingtech.com"; classtype:trojan-activity; sid:100002710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freecnetdownload.com"; classtype:trojan-activity; sid:100002711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freisites.com.br"; classtype:trojan-activity; sid:100002712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ftp.n3twork30cm.ml"; classtype:trojan-activity; sid:100002713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fullelectronica.com.ar"; classtype:trojan-activity; sid:100002714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"funletters.net"; classtype:trojan-activity; sid:100002715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fusionfiresolutions.com"; classtype:trojan-activity; sid:100002716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"futbolpr.com"; classtype:trojan-activity; sid:100002717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"futuregraphics.com.ar"; classtype:trojan-activity; sid:100002718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"g.pinmonkey.xyz"; classtype:trojan-activity; sid:100002719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gametwogame.com"; classtype:trojan-activity; sid:100002720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garciadogshow.com"; classtype:trojan-activity; sid:100002721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow.myvnc.com"; classtype:trojan-activity; sid:100002722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow4.myvnc.com"; classtype:trojan-activity; sid:100002723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gastoudergonny.nl"; classtype:trojan-activity; sid:100002724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gbbulls.co.uk"; classtype:trojan-activity; sid:100002725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gcpc.co.id.chronoscurtain.com"; classtype:trojan-activity; sid:100002726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"generaldeviales.com"; classtype:trojan-activity; sid:100002727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfmodd1.webselffiles01.com"; classtype:trojan-activity; sid:100002728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfold1.webselffiles01.com"; classtype:trojan-activity; sid:100002729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghettohub.co.za"; classtype:trojan-activity; sid:100002730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghislain.dartois.pagesperso-orange.fr"; classtype:trojan-activity; sid:100002731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giadungg7.com"; classtype:trojan-activity; sid:100002732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giddos.ga"; classtype:trojan-activity; sid:100002733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"glowinmedia.co.ke"; classtype:trojan-activity; sid:100002734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmsebpl.com"; classtype:trojan-activity; sid:100002735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmtransformationacademy.com"; classtype:trojan-activity; sid:100002736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmvadmission.org"; classtype:trojan-activity; sid:100002737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnimelf.net"; classtype:trojan-activity; sid:100002738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnscrew.ro"; classtype:trojan-activity; sid:100002739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gold.investforex.id"; classtype:trojan-activity; sid:100002740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcake.co.id"; classtype:trojan-activity; sid:100002741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com"; classtype:trojan-activity; sid:100002742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com.au"; classtype:trojan-activity; sid:100002743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"golden-memories-funerals.yourpageserver.com"; classtype:trojan-activity; sid:100002744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldenasiacapital.com"; classtype:trojan-activity; sid:100002745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gorecycle.fahadjutt.com"; classtype:trojan-activity; sid:100002746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gpotecnosystems.com"; classtype:trojan-activity; sid:100002747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gracejukes.com"; classtype:trojan-activity; sid:100002748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"grovershospital.com"; classtype:trojan-activity; sid:100002749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"grupoinmare.com"; classtype:trojan-activity; sid:100002750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gruposelt.000webhostapp.com"; classtype:trojan-activity; sid:100002751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gruppodomus.com.br"; classtype:trojan-activity; sid:100002752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gs.monerorx.com"; classtype:trojan-activity; sid:100002753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"guide-to-cell-phones.com"; classtype:trojan-activity; sid:100002754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gulfac-house.com"; classtype:trojan-activity; sid:100002755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gvpcdpgc.edu.in"; classtype:trojan-activity; sid:100002756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"habbotips.free.fr"; classtype:trojan-activity; sid:100002757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hagebakken.no"; classtype:trojan-activity; sid:100002758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hamptonpartyoffive.com"; classtype:trojan-activity; sid:100002759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hashmati.com"; classtype:trojan-activity; sid:100002760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hassanproduct.com"; classtype:trojan-activity; sid:100002761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hchfug.org"; classtype:trojan-activity; sid:100002762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hd11315.com"; classtype:trojan-activity; sid:100002763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hdkamera2003.hu"; classtype:trojan-activity; sid:100002764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hds.sz4h.com"; classtype:trojan-activity; sid:100002765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"heavymaq.cl"; classtype:trojan-activity; sid:100002766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hellogorgeous.com.au"; classtype:trojan-activity; sid:100002767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"help.hizuko.com"; classtype:trojan-activity; sid:100002768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"herchinfitout.com.sg"; classtype:trojan-activity; sid:100002769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hhaward.org"; classtype:trojan-activity; sid:100002770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandroadcoc.com"; classtype:trojan-activity; sid:100002771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandslasvegas.atakdev.com"; classtype:trojan-activity; sid:100002772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hindi.factsriver.com"; classtype:trojan-activity; sid:100002773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hiptool.net"; classtype:trojan-activity; sid:100002774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitpe.com"; classtype:trojan-activity; sid:100002775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitstation.nl"; classtype:trojan-activity; sid:100002776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hmpmall.co.kr"; classtype:trojan-activity; sid:100002777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoagietesting10.com"; classtype:trojan-activity; sid:100002778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoayeuthuong-my.sharepoint.com"; classtype:trojan-activity; sid:100002779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"holmesservices.mobiledevsite.co"; classtype:trojan-activity; sid:100002780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"homefindersolutions.com"; classtype:trojan-activity; sid:100002781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hongluosi.com"; classtype:trojan-activity; sid:100002782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hookedupboatclub.com"; classtype:trojan-activity; sid:100002783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hortizwp.eastus.cloudapp.azure.com"; classtype:trojan-activity; sid:100002784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostingparacolombia.com"; classtype:trojan-activity; sid:100002785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostzaa.com"; classtype:trojan-activity; sid:100002786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"houstonshutters.site"; classtype:trojan-activity; sid:100002787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hr2019.vrcom7.com"; classtype:trojan-activity; sid:100002788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hrnautica.com.br"; classtype:trojan-activity; sid:100002789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hseda.com"; classtype:trojan-activity; sid:100002790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hsmwebapp.com"; classtype:trojan-activity; sid:100002791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"htownbars.com"; classtype:trojan-activity; sid:100002792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hubtech.co.za"; classtype:trojan-activity; sid:100002793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"huellacero.cl"; classtype:trojan-activity; sid:100002794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hunggiang.vn"; classtype:trojan-activity; sid:100002795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"husamiyahschool.com"; classtype:trojan-activity; sid:100002796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iabmixx2020.rayadigital.online"; classtype:trojan-activity; sid:100002797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iam313.com"; classtype:trojan-activity; sid:100002798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iammdshanto.com"; classtype:trojan-activity; sid:100002799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"icon.shatangmu.cn"; classtype:trojan-activity; sid:100002800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idilsoft.com"; classtype:trojan-activity; sid:100002801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idj.no"; classtype:trojan-activity; sid:100002802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idvindia.com"; classtype:trojan-activity; sid:100002803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ieclb.com.br"; classtype:trojan-activity; sid:100002804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ikexpert.com"; classtype:trojan-activity; sid:100002805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ilrafrica.com"; classtype:trojan-activity; sid:100002806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"images.jermiau.com"; classtype:trojan-activity; sid:100002807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"imbueautoworx.co.za"; classtype:trojan-activity; sid:100002808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"in-tune2016.com"; classtype:trojan-activity; sid:100002809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incrediblepixels.com"; classtype:trojan-activity; sid:100002810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incredicole.com"; classtype:trojan-activity; sid:100002811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"indrasbikaner.com"; classtype:trojan-activity; sid:100002812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infair.vn"; classtype:trojan-activity; sid:100002813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infovator.com"; classtype:trojan-activity; sid:100002814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"initialnetworks.com"; classtype:trojan-activity; sid:100002815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inodesthetotaldesigners.com"; classtype:trojan-activity; sid:100002816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inrajahmundry.co.in"; classtype:trojan-activity; sid:100002817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"insignificantfinecore.testmail4.repl.co"; classtype:trojan-activity; sid:100002818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"instantindialoan.com"; classtype:trojan-activity; sid:100002819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"insupportofchildren.co.uk"; classtype:trojan-activity; sid:100002820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intellectsmart.in"; classtype:trojan-activity; sid:100002821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intersel-idf.org"; classtype:trojan-activity; sid:100002822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intuitiveideas.com.my"; classtype:trojan-activity; sid:100002823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inversiones.arrayanfinanciero.cl"; classtype:trojan-activity; sid:100002824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"invest.xpcorporative.com.br"; classtype:trojan-activity; sid:100002825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"investinae.com"; classtype:trojan-activity; sid:100002826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ioabc.wif.com.br"; classtype:trojan-activity; sid:100002827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ipmes.ma"; classtype:trojan-activity; sid:100002828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iremart.es"; classtype:trojan-activity; sid:100002829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iris101.co.uk"; classtype:trojan-activity; sid:100002830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iscamenabe.com"; classtype:trojan-activity; sid:100002831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isiphephelocon.co.za"; classtype:trojan-activity; sid:100002832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iso-dubai.net"; classtype:trojan-activity; sid:100002833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"israrulhaq.me"; classtype:trojan-activity; sid:100002834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isso.ps"; classtype:trojan-activity; sid:100002835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ist-security.com"; classtype:trojan-activity; sid:100002836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"it123.ru"; classtype:trojan-activity; sid:100002837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"italiandirezione.casa"; classtype:trojan-activity; sid:100002838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itc-demo.softgig.co.ke"; classtype:trojan-activity; sid:100002839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itelsys.ma"; classtype:trojan-activity; sid:100002840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jacktech.jackindia.com"; classtype:trojan-activity; sid:100002841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jaishritours.com"; classtype:trojan-activity; sid:100002842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamiekaylive.com"; classtype:trojan-activity; sid:100002843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamshed.pk"; classtype:trojan-activity; sid:100002844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jansen-heesch.nl"; classtype:trojan-activity; sid:100002845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jathra.co.uk"; classtype:trojan-activity; sid:100002846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jay.diamondrelationscrm.us"; classtype:trojan-activity; sid:100002847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jebs.net.au"; classtype:trojan-activity; sid:100002848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jeffdahlke.com"; classtype:trojan-activity; sid:100002849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jennwolfemtb.com"; classtype:trojan-activity; sid:100002850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jhayesconsulting.com"; classtype:trojan-activity; sid:100002851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jiaoyuzixun.cn"; classtype:trojan-activity; sid:100002852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jing-da.com.tw"; classtype:trojan-activity; sid:100002853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jnanbharati.com"; classtype:trojan-activity; sid:100002854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jobs.thebeessolution.com"; classtype:trojan-activity; sid:100002855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"joelbonissilver.com"; classtype:trojan-activity; sid:100002856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"join.cl8movement.co.za"; classtype:trojan-activity; sid:100002857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"josegene.com"; classtype:trojan-activity; sid:100002858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jpwoodfordco.com"; classtype:trojan-activity; sid:100002859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jumpmanualjacobhiller.com"; classtype:trojan-activity; sid:100002860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jupiter.toxsl.in"; classtype:trojan-activity; sid:100002861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"justinscott.com.au"; classtype:trojan-activity; sid:100002862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kadigital.co.uk"; classtype:trojan-activity; sid:100002863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalawatihomes.com"; classtype:trojan-activity; sid:100002864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalogirosfinance.com"; classtype:trojan-activity; sid:100002865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kaptaanchapal.com"; classtype:trojan-activity; sid:100002866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"karer.by"; classtype:trojan-activity; sid:100002867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"katanvetov.co.il"; classtype:trojan-activity; sid:100002868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kensingtondriving.com"; classtype:trojan-activity; sid:100002869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ketofitnessexpert.com"; classtype:trojan-activity; sid:100002870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kevinjewelry.com.co"; classtype:trojan-activity; sid:100002871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"keywatch.yourpageserver.com"; classtype:trojan-activity; sid:100002872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kingssa.co.za"; classtype:trojan-activity; sid:100002873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kjcpromo.com"; classtype:trojan-activity; sid:100002874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kleinendeli.co.za"; classtype:trojan-activity; sid:100002875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"korrectconceptservices.com"; classtype:trojan-activity; sid:100002876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"krisbadminton.com"; classtype:trojan-activity; sid:100002877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ktb.sch.id"; classtype:trojan-activity; sid:100002878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kubatoglubaklava.com.tr"; classtype:trojan-activity; sid:100002879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kumaralok.in"; classtype:trojan-activity; sid:100002880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kwanfromhongkong.com"; classtype:trojan-activity; sid:100002881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kz.sldov.ru"; classtype:trojan-activity; sid:100002882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lacasadelosalebrijes.com"; classtype:trojan-activity; sid:100002883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ladylabonde.com"; classtype:trojan-activity; sid:100002884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lameguard.ru"; classtype:trojan-activity; sid:100002885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laodongnhat.vn"; classtype:trojan-activity; sid:100002886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laravel.pointersoftwares.com.br"; classtype:trojan-activity; sid:100002887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lasermobilesounds.co.uk"; classtype:trojan-activity; sid:100002888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laura9630fr.com"; classtype:trojan-activity; sid:100002889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lauratomismith.com"; classtype:trojan-activity; sid:100002890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lautarosanmiguel.com"; classtype:trojan-activity; sid:100002891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lawforall.edu.lk"; classtype:trojan-activity; sid:100002892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lawschoolideas.xyz"; classtype:trojan-activity; sid:100002893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lceventos.net"; classtype:trojan-activity; sid:100002894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ld.mediaget.com"; classtype:trojan-activity; sid:100002895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ldgcorp.com"; classtype:trojan-activity; sid:100002896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"learning.real-academy.net"; classtype:trojan-activity; sid:100002897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leasiacherise.com"; classtype:trojan-activity; sid:100002898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leczkregoslup.acelero.pl"; classtype:trojan-activity; sid:100002899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"legend.nu"; classtype:trojan-activity; sid:100002900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leluibuffet.com.br"; classtype:trojan-activity; sid:100002901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lestesteux.ca"; classtype:trojan-activity; sid:100002902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"libantravel.pl"; classtype:trojan-activity; sid:100002903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.arihantmbainstitute.ac.in"; classtype:trojan-activity; sid:100002904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.uib.ac.id"; classtype:trojan-activity; sid:100002905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lidoraggiodisole.it"; classtype:trojan-activity; sid:100002906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lifebeam.elin.co.za"; classtype:trojan-activity; sid:100002907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lindnerelektroanlagen.de"; classtype:trojan-activity; sid:100002908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"linkintec.cn"; classtype:trojan-activity; sid:100002909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"liquidaz.casa"; classtype:trojan-activity; sid:100002910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"livetrack.in"; classtype:trojan-activity; sid:100002911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lloydsindian.co.uk"; classtype:trojan-activity; sid:100002912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lm.stagingarea.co.za"; classtype:trojan-activity; sid:100002913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lmaancha.co.il"; classtype:trojan-activity; sid:100002914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.cstdevs.com"; classtype:trojan-activity; sid:100002915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.login2.in"; classtype:trojan-activity; sid:100002916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"location-voitures.ma"; classtype:trojan-activity; sid:100002917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"login.trezor.com.stockfootagesindia.com"; classtype:trojan-activity; sid:100002918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"logotypfabriken.se"; classtype:trojan-activity; sid:100002919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotix.de"; classtype:trojan-activity; sid:100002920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotusanddragonfly.com"; classtype:trojan-activity; sid:100002921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.definerisco.com"; classtype:trojan-activity; sid:100002922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.difusodesign.com"; classtype:trojan-activity; sid:100002923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.quama.pe"; classtype:trojan-activity; sid:100002924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ltc.typoten.com"; classtype:trojan-activity; sid:100002925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luminouspneuma.com"; classtype:trojan-activity; sid:100002926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luxomodels.com"; classtype:trojan-activity; sid:100002927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m-technics.kz"; classtype:trojan-activity; sid:100002928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m.estudiomoros.com.ar"; classtype:trojan-activity; sid:100002929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m.mobilelocalsales.com"; classtype:trojan-activity; sid:100002930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"madicon.co.za"; classtype:trojan-activity; sid:100002931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"magianegramagiablancayamarres.com"; classtype:trojan-activity; sid:100002932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.bs-eiendomme.co.za"; classtype:trojan-activity; sid:100002933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.golimoapp.com"; classtype:trojan-activity; sid:100002934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.jeffsono.org"; classtype:trojan-activity; sid:100002935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maksi.feb.unib.ac.id"; classtype:trojan-activity; sid:100002936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malaya.tv"; classtype:trojan-activity; sid:100002937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malwarecoding.github.io"; classtype:trojan-activity; sid:100002938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managed.oss-cn-beijing.aliyuncs.com"; classtype:trojan-activity; sid:100002939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managemysalon.in"; classtype:trojan-activity; sid:100002940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manantialesdelnorte.uy"; classtype:trojan-activity; sid:100002941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mangalyaa.lk"; classtype:trojan-activity; sid:100002942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manhtien.net"; classtype:trojan-activity; sid:100002943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marcapinyo.ru"; classtype:trojan-activity; sid:100002944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mario-sunjic.com"; classtype:trojan-activity; sid:100002945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariobrown.net"; classtype:trojan-activity; sid:100002946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariotessarollo.com"; classtype:trojan-activity; sid:100002947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketinfosales.com"; classtype:trojan-activity; sid:100002948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marksidfgs.ug"; classtype:trojan-activity; sid:100002949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"masjidhabeebiyarazviya.mysunni.com"; classtype:trojan-activity; sid:100002950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mastersofclientretention.com.au"; classtype:trojan-activity; sid:100002951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"masterthedaybook.com"; classtype:trojan-activity; sid:100002952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"materialescantu.com"; classtype:trojan-activity; sid:100002953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"matruchhaya.co.in"; classtype:trojan-activity; sid:100002954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maxiquim.cl"; classtype:trojan-activity; sid:100002955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maxoprint.co.uk"; classtype:trojan-activity; sid:100002956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maxtox.com.pk"; classtype:trojan-activity; sid:100002957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maybethescobar.com"; classtype:trojan-activity; sid:100002958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbgrm.com"; classtype:trojan-activity; sid:100002959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbjtimes.com"; classtype:trojan-activity; sid:100002960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbsolutions.ge"; classtype:trojan-activity; sid:100002961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbx.com.au"; classtype:trojan-activity; sid:100002962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mdasa.elin.co.za"; classtype:trojan-activity; sid:100002963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medevlb.org"; classtype:trojan-activity; sid:100002964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"media-server.skyinternet.com.pk"; classtype:trojan-activity; sid:100002965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medianews.ge"; classtype:trojan-activity; sid:100002966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mediawaysnews.com"; classtype:trojan-activity; sid:100002967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medistaffconsulting.com"; classtype:trojan-activity; sid:100002968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meeweb.com"; classtype:trojan-activity; sid:100002969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"megagynreformas.com.br"; classtype:trojan-activity; sid:100002970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"megamart.afnan-amc.com"; classtype:trojan-activity; sid:100002971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mehainteriors.com"; classtype:trojan-activity; sid:100002972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"melissaleiteestetica.com.br"; classtype:trojan-activity; sid:100002973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mercabits.com"; classtype:trojan-activity; sid:100002974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"merkathink.com"; classtype:trojan-activity; sid:100002975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mertlog.com"; classtype:trojan-activity; sid:100002976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"metaflip.io"; classtype:trojan-activity; sid:100002977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"metalin-cr.com"; classtype:trojan-activity; sid:100002978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mettaanand.org"; classtype:trojan-activity; sid:100002979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meuoculosnanet.com.br"; classtype:trojan-activity; sid:100002980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mfevr.com"; classtype:trojan-activity; sid:100002981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot.myvnc.com"; classtype:trojan-activity; sid:100002982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot80.myvnc.com"; classtype:trojan-activity; sid:100002983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"micalle.com.au"; classtype:trojan-activity; sid:100002984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michaelphilip.com"; classtype:trojan-activity; sid:100002985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michimal2.000webhostapp.com"; classtype:trojan-activity; sid:100002986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microblading.mirliandias.com.br"; classtype:trojan-activity; sid:100002987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microcomm-group.com"; classtype:trojan-activity; sid:100002988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mingguanwms.com"; classtype:trojan-activity; sid:100002989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"minuevavida.org"; classtype:trojan-activity; sid:100002990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mirror.mypage.sk"; classtype:trojan-activity; sid:100002991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"misterson.com"; classtype:trojan-activity; sid:100002992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mixr.at"; classtype:trojan-activity; sid:100002993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mkontakt.az"; classtype:trojan-activity; sid:100002994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mktf.mx"; classtype:trojan-activity; sid:100002995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mmdx.com"; classtype:trojan-activity; sid:100002996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mmogollon.com.mx"; classtype:trojan-activity; sid:100002997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mncarteam.com"; classtype:trojan-activity; sid:100002998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mobile.illumetechnology.com"; classtype:trojan-activity; sid:100002999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modelhouseturkey.com"; classtype:trojan-activity; sid:100003000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modernmanna.org"; classtype:trojan-activity; sid:100003001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"monetization.business"; classtype:trojan-activity; sid:100003002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"moninediy.com"; classtype:trojan-activity; sid:100003003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mopai.sg"; classtype:trojan-activity; sid:100003004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"moreirawag.ac.ug"; classtype:trojan-activity; sid:100003005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"motorcomunicacion.com"; classtype:trojan-activity; sid:100003006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"msacontabil.com.br"; classtype:trojan-activity; sid:100003007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mtspsmjeli.sch.id"; classtype:trojan-activity; sid:100003008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mumgee.co.za"; classtype:trojan-activity; sid:100003009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mundialdebienes.net"; classtype:trojan-activity; sid:100003010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mundotecnologiasolar.com"; classtype:trojan-activity; sid:100003011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"musaffirtours.com"; classtype:trojan-activity; sid:100003012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"muzimbiti.xigubo.co.mz"; classtype:trojan-activity; sid:100003013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mxpiqw.am.files.1drv.com"; classtype:trojan-activity; sid:100003014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mydatebook.in"; classtype:trojan-activity; sid:100003015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mymlql.com"; classtype:trojan-activity; sid:100003016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myritz.vettickal.com"; classtype:trojan-activity; sid:100003017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mysalons.in"; classtype:trojan-activity; sid:100003018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myscape.in"; classtype:trojan-activity; sid:100003019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mysura.it"; classtype:trojan-activity; sid:100003020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"naeemacademy.com"; classtype:trojan-activity; sid:100003021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"namnyak.co.ke"; classtype:trojan-activity; sid:100003022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nap.mgsservers.com"; classtype:trojan-activity; sid:100003023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"narcissisto.com"; classtype:trojan-activity; sid:100003024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"narimohol.com"; classtype:trojan-activity; sid:100003025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"navayurveda.in"; classtype:trojan-activity; sid:100003026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nec-i.com"; classtype:trojan-activity; sid:100003027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nedkellymyanmar.com"; classtype:trojan-activity; sid:100003028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nelitrianggraeni.000webhostapp.com"; classtype:trojan-activity; sid:100003029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nerve.untergrund.net"; classtype:trojan-activity; sid:100003030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nettube.com.br"; classtype:trojan-activity; sid:100003031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"networkwheels.co.za"; classtype:trojan-activity; sid:100003032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neuroenergy.fahadjutt.com"; classtype:trojan-activity; sid:100003033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neuromedic.com.br"; classtype:trojan-activity; sid:100003034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newfuture.fr"; classtype:trojan-activity; sid:100003035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newinfinitysynergy.com"; classtype:trojan-activity; sid:100003036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newtreedesign.co.uk"; classtype:trojan-activity; sid:100003037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newvisionopticallab.com"; classtype:trojan-activity; sid:100003038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newxing.com"; classtype:trojan-activity; sid:100003039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nextdigitalday.ru"; classtype:trojan-activity; sid:100003040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ngdaycare.co.za"; classtype:trojan-activity; sid:100003041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nguyenkekhuyen.com"; classtype:trojan-activity; sid:100003042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nhorangtreem.com"; classtype:trojan-activity; sid:100003043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nicolas.ug"; classtype:trojan-activity; sid:100003044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nidhi.iexist.in"; classtype:trojan-activity; sid:100003045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nikanpolimer.ir"; classtype:trojan-activity; sid:100003046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilehouse.co.ug"; classtype:trojan-activity; sid:100003047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilinkeji.com"; classtype:trojan-activity; sid:100003048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nimboohomes.com"; classtype:trojan-activity; sid:100003049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"njtiledesigncenter.com"; classtype:trojan-activity; sid:100003050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nobius.org"; classtype:trojan-activity; sid:100003051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nocalnoodle.elin.co.za"; classtype:trojan-activity; sid:100003052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nomadicbees.com"; classtype:trojan-activity; sid:100003053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nonnarina.ax"; classtype:trojan-activity; sid:100003054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"notamuzikaletleri.com"; classtype:trojan-activity; sid:100003055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ns1.the-widyantos.com"; classtype:trojan-activity; sid:100003056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nsb.org.uk"; classtype:trojan-activity; sid:100003057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nurmarkaz.org"; classtype:trojan-activity; sid:100003058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nxtnet.ga"; classtype:trojan-activity; sid:100003059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nyasabigbullets.com"; classtype:trojan-activity; sid:100003060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nyeh2o.com.au"; classtype:trojan-activity; sid:100003061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oakleyandfriends.co.uk"; classtype:trojan-activity; sid:100003062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"obseques-conseils.com"; classtype:trojan-activity; sid:100003063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oecteam.com"; classtype:trojan-activity; sid:100003064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohe.ie"; classtype:trojan-activity; sid:100003065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohsewgorgeous.co.uk"; classtype:trojan-activity; sid:100003066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oknoplastik.sk"; classtype:trojan-activity; sid:100003067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oleholeh.memangbeda.website"; classtype:trojan-activity; sid:100003068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaia.org"; classtype:trojan-activity; sid:100003069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaromatic.com"; classtype:trojan-activity; sid:100003070; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omega.az"; classtype:trojan-activity; sid:100003071; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oms.pappai.com"; classtype:trojan-activity; sid:100003072; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omscoc.pappai.com"; classtype:trojan-activity; sid:100003073; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedrive.listifyapp.co"; classtype:trojan-activity; sid:100003074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"online.creedglobal.in"; classtype:trojan-activity; sid:100003075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onlinestatis.bar"; classtype:trojan-activity; sid:100003076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"open.warehousesaas.co.uk"; classtype:trojan-activity; sid:100003077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"opentoronto.org"; classtype:trojan-activity; sid:100003078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"opolis.io"; classtype:trojan-activity; sid:100003079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"optimus.com.sg"; classtype:trojan-activity; sid:100003080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"order.bizpeed.com"; classtype:trojan-activity; sid:100003081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orientgatewayltd.com"; classtype:trojan-activity; sid:100003082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orion445.com"; classtype:trojan-activity; sid:100003083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oserve.pk"; classtype:trojan-activity; sid:100003084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ot.weenets.com"; classtype:trojan-activity; sid:100003085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"otolithenrichment.fahadjutt.com"; classtype:trojan-activity; sid:100003086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"outletdosaquecedores.com.br"; classtype:trojan-activity; sid:100003087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ozemag.com"; classtype:trojan-activity; sid:100003088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p1.lingpao8.com"; classtype:trojan-activity; sid:100003089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p3.zbjimg.com"; classtype:trojan-activity; sid:100003090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p6.zbjimg.com"; classtype:trojan-activity; sid:100003091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pablobrothel.com.ar"; classtype:trojan-activity; sid:100003092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacificgroup.ws"; classtype:trojan-activity; sid:100003093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacwebdesigns.com"; classtype:trojan-activity; sid:100003094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pagos.krayem.com.mx"; classtype:trojan-activity; sid:100003095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"palbas.cl"; classtype:trojan-activity; sid:100003096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"palochusvet.szm.com"; classtype:trojan-activity; sid:100003097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pamperpartypros.co.za"; classtype:trojan-activity; sid:100003098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parallel.rockvideos.at"; classtype:trojan-activity; sid:100003099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parejasfelices.mi-fs.com"; classtype:trojan-activity; sid:100003100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parkhussion.com"; classtype:trojan-activity; sid:100003101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"partharaj.me"; classtype:trojan-activity; sid:100003102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"partsapp.com.br"; classtype:trojan-activity; sid:100003103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pastorpaulocosta.com"; classtype:trojan-activity; sid:100003104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.51lg.com"; classtype:trojan-activity; sid:100003105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.99ddd.com"; classtype:trojan-activity; sid:100003106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch3.99ddd.com"; classtype:trojan-activity; sid:100003107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paths.elin.co.za"; classtype:trojan-activity; sid:100003108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patriotsupremehemp.com"; classtype:trojan-activity; sid:100003109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paulmercier.biz"; classtype:trojan-activity; sid:100003110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payerrealty.com"; classtype:trojan-activity; sid:100003111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payments.atifsiddiqui.me"; classtype:trojan-activity; sid:100003112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pcsoori.com"; classtype:trojan-activity; sid:100003113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pd.oceaniarp.net"; classtype:trojan-activity; sid:100003114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pemdodo.com"; classtype:trojan-activity; sid:100003115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perfumeriamontes.es"; classtype:trojan-activity; sid:100003116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpus.onlineman7-jombang.sch.id"; classtype:trojan-activity; sid:100003117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpustekim.untirta.ac.id"; classtype:trojan-activity; sid:100003118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pestoclean.co.uk"; classtype:trojan-activity; sid:100003119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"petercollie.com"; classtype:trojan-activity; sid:100003120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"petroindia.co.in"; classtype:trojan-activity; sid:100003121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ph4s.ru"; classtype:trojan-activity; sid:100003122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phasdesign.com"; classtype:trojan-activity; sid:100003123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phenhuong.sanpham.online"; classtype:trojan-activity; sid:100003124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phittc.com"; classtype:trojan-activity; sid:100003125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"photo360.kubooking.com"; classtype:trojan-activity; sid:100003126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pink99.com"; classtype:trojan-activity; sid:100003127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pinkpaprika.co.uk"; classtype:trojan-activity; sid:100003128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"plasfan.ind.br"; classtype:trojan-activity; sid:100003129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"platinumherbal.com"; classtype:trojan-activity; sid:100003130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"playground2.grupoaliadasca.com"; classtype:trojan-activity; sid:100003131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pmglance.startwriteup.com"; classtype:trojan-activity; sid:100003132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pointactionsg.com"; classtype:trojan-activity; sid:100003133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pokojewewladyslawowie.pl"; classtype:trojan-activity; sid:100003134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pole.com.vc"; classtype:trojan-activity; sid:100003135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pool.phxdir.com"; classtype:trojan-activity; sid:100003136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pooltablemoversdenver.net"; classtype:trojan-activity; sid:100003137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"portal.premiumpunch.com"; classtype:trojan-activity; sid:100003138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"posmicrosystems.com"; classtype:trojan-activity; sid:100003139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"poulman.panagiotopoulos-tours.gr"; classtype:trojan-activity; sid:100003140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ppdb.smk-ciptaskill.sch.id"; classtype:trojan-activity; sid:100003141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestasicash.com.ar"; classtype:trojan-activity; sid:100003142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestigehomeautomation.net"; classtype:trojan-activity; sid:100003143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"preview2.behalen.com"; classtype:trojan-activity; sid:100003144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prishaartcreations.com"; classtype:trojan-activity; sid:100003145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"production.sparshims.com"; classtype:trojan-activity; sid:100003146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"programaoperadoronline.com.br"; classtype:trojan-activity; sid:100003147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"project.exquitec.com"; classtype:trojan-activity; sid:100003148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promotapp.com"; classtype:trojan-activity; sid:100003149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promotoradescomplica.com.br"; classtype:trojan-activity; sid:100003150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promoversdubai.com"; classtype:trojan-activity; sid:100003151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq.elin.co.za"; classtype:trojan-activity; sid:100003152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq2.elin.co.za"; classtype:trojan-activity; sid:100003153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosoc.nl"; classtype:trojan-activity; sid:100003154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosupport.cl"; classtype:trojan-activity; sid:100003155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosyarmakassar.com"; classtype:trojan-activity; sid:100003156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"provence.elin.co.za"; classtype:trojan-activity; sid:100003157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prueba.danielluza.com"; classtype:trojan-activity; sid:100003158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pujashoppe.in"; classtype:trojan-activity; sid:100003159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punchdialogues.com"; classtype:trojan-activity; sid:100003160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punjabdevelopersassociation.com.pk"; classtype:trojan-activity; sid:100003161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pvcprinting.co.uk"; classtype:trojan-activity; sid:100003162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qadir.tickfa.ir"; classtype:trojan-activity; sid:100003163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qatarglobalconsulting.com"; classtype:trojan-activity; sid:100003164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qmsled.com"; classtype:trojan-activity; sid:100003165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"quartier-midi.be"; classtype:trojan-activity; sid:100003166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"querocar.com"; classtype:trojan-activity; sid:100003167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rachmat-assuhaimi.my.id"; classtype:trojan-activity; sid:100003168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"radioafifense.deploys.live"; classtype:trojan-activity; sid:100003169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rainbowisp.info"; classtype:trojan-activity; sid:100003170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rajeshtailang.com"; classtype:trojan-activity; sid:100003171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rakeshkhatri.in"; classtype:trojan-activity; sid:100003172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"raodigitalmedia.com"; classtype:trojan-activity; sid:100003173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"raquelhelena.com.br"; classtype:trojan-activity; sid:100003174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rarlabarchiver.ac"; classtype:trojan-activity; sid:100003175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rasadbar.ir"; classtype:trojan-activity; sid:100003176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rashika.ascarvalho.co.za"; classtype:trojan-activity; sid:100003177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ratemyfenancialadvisor.com"; classtype:trojan-activity; sid:100003178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ravenproductionsltd.com"; classtype:trojan-activity; sid:100003179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rc.ixiaoyang.cn"; classtype:trojan-activity; sid:100003180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rcmesilva.charbelsales.com.br"; classtype:trojan-activity; sid:100003181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reacredit.com.br"; classtype:trojan-activity; sid:100003182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"readymmade.com"; classtype:trojan-activity; sid:100003183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"recyclethesurplus.com"; classtype:trojan-activity; sid:100003184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"redbats.co.in"; classtype:trojan-activity; sid:100003185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"redchillicrackers.com"; classtype:trojan-activity; sid:100003186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reifenquick.de"; classtype:trojan-activity; sid:100003187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"relaxindulge.co.nz"; classtype:trojan-activity; sid:100003188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"renehavis.com.ua"; classtype:trojan-activity; sid:100003189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"repatriacioncolombia.com"; classtype:trojan-activity; sid:100003190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"res.uf1.cn"; classtype:trojan-activity; sid:100003191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reseller.digimitra.in"; classtype:trojan-activity; sid:100003192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reseller.itechbrasil.com"; classtype:trojan-activity; sid:100003193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"resuco.net"; classtype:trojan-activity; sid:100003194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rezkabum.ru"; classtype:trojan-activity; sid:100003195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rhema.com.sg"; classtype:trojan-activity; sid:100003196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"richancyber.info"; classtype:trojan-activity; sid:100003197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"richmondminerals.co.zm"; classtype:trojan-activity; sid:100003198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinaefoundation.org.za"; classtype:trojan-activity; sid:100003199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinkaisystem-ht.com"; classtype:trojan-activity; sid:100003200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"riverfox.co.za"; classtype:trojan-activity; sid:100003201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkcable.co.in"; classtype:trojan-activity; sid:100003202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkverify.securestudies.com"; classtype:trojan-activity; sid:100003203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertmcardle.com"; classtype:trojan-activity; sid:100003204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertsinclair.net"; classtype:trojan-activity; sid:100003205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"romanianpoints.com"; classtype:trojan-activity; sid:100003206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ronnietucker.co.uk"; classtype:trojan-activity; sid:100003207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roomsvc.servegate.kr"; classtype:trojan-activity; sid:100003208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roshnijewellery.com"; classtype:trojan-activity; sid:100003209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rsgym.net"; classtype:trojan-activity; sid:100003210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubazar.pro"; classtype:trojan-activity; sid:100003211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubycityvietnam.com"; classtype:trojan-activity; sid:100003212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruisgood.ru"; classtype:trojan-activity; sid:100003213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruwadalkuwait.com"; classtype:trojan-activity; sid:100003214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rydchile.cl"; classtype:trojan-activity; sid:100003215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.51shijuan.com"; classtype:trojan-activity; sid:100003216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.thechinesemuslim.com"; classtype:trojan-activity; sid:100003217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sac2.11xii.com"; classtype:trojan-activity; sid:100003218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sacredscentsonline.com"; classtype:trojan-activity; sid:100003219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sadmahfuneralservices.co.za"; classtype:trojan-activity; sid:100003220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safcol-colors.com"; classtype:trojan-activity; sid:100003221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safehubsecurity.ca"; classtype:trojan-activity; sid:100003222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safety.nanotechproautocare.com"; classtype:trojan-activity; sid:100003223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sahathaikasetpan.com"; classtype:trojan-activity; sid:100003224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sainzim.co.za"; classtype:trojan-activity; sid:100003225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"saisoftwareinc.com"; classtype:trojan-activity; sid:100003226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"salecorner.yourpageserver.com"; classtype:trojan-activity; sid:100003227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"salonsaifa.com"; classtype:trojan-activity; sid:100003228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"samriddhijyotish.com"; classtype:trojan-activity; sid:100003229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sandovalgraphics.com"; classtype:trojan-activity; sid:100003230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"santyago.org"; classtype:trojan-activity; sid:100003231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sasystemsuk.com"; classtype:trojan-activity; sid:100003232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scaladevelopments.scaladevco.com"; classtype:trojan-activity; sid:100003233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scarfaceindustries.com"; classtype:trojan-activity; sid:100003234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scglobal.co.th"; classtype:trojan-activity; sid:100003235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schalke04rss.de"; classtype:trojan-activity; sid:100003236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scheff.com"; classtype:trojan-activity; sid:100003237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schoolbustracker.softgig.co.ke"; classtype:trojan-activity; sid:100003238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sculetus.nl"; classtype:trojan-activity; sid:100003239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"secure-doc-reader.com"; classtype:trojan-activity; sid:100003240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"segalsmetals.elin.co.za"; classtype:trojan-activity; sid:100003241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sellmyphonela.com"; classtype:trojan-activity; sid:100003242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"selltechtoday.com"; classtype:trojan-activity; sid:100003243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"senbiaojita.com"; classtype:trojan-activity; sid:100003244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sentierodelviandante.ml"; classtype:trojan-activity; sid:100003245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"serendibsourcing.com"; classtype:trojan-activity; sid:100003246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sericaasia.com"; classtype:trojan-activity; sid:100003247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd.myvnc.com"; classtype:trojan-activity; sid:100003248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd80.myvnc.com"; classtype:trojan-activity; sid:100003249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sexologistpakistan.net"; classtype:trojan-activity; sid:100003250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sgb.ac.ke"; classtype:trojan-activity; sid:100003251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sgessy.com.br"; classtype:trojan-activity; sid:100003252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shaheentbfoundation.com"; classtype:trojan-activity; sid:100003253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shahikhana.cstdevs.com"; classtype:trojan-activity; sid:100003254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shahu66.com"; classtype:trojan-activity; sid:100003255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharkrigs.com"; classtype:trojan-activity; sid:100003256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharpelevators.in"; classtype:trojan-activity; sid:100003257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shembefoundation.com"; classtype:trojan-activity; sid:100003258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shivakunwar.com.np"; classtype:trojan-activity; sid:100003259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shoblasaathitrust.org"; classtype:trojan-activity; sid:100003260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shooka-co.com"; classtype:trojan-activity; sid:100003261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shop.goldspot.agency"; classtype:trojan-activity; sid:100003262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shopsofe.com"; classtype:trojan-activity; sid:100003263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shrinikelectrical.co.za"; classtype:trojan-activity; sid:100003264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sibernetix.fr"; classtype:trojan-activity; sid:100003265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sige.brisainformatica.com.br"; classtype:trojan-activity; sid:100003266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"signatureads.co.in"; classtype:trojan-activity; sid:100003267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siili.net"; classtype:trojan-activity; sid:100003268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simoneporzi.it"; classtype:trojan-activity; sid:100003269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simorsint.com"; classtype:trojan-activity; sid:100003270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simplithy.co.uk"; classtype:trojan-activity; sid:100003271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindicato1ucm.cl"; classtype:trojan-activity; sid:100003272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindpol.tiejuris.com.br"; classtype:trojan-activity; sid:100003273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sinergidwireka.com"; classtype:trojan-activity; sid:100003274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sipahielektrik.com"; classtype:trojan-activity; sid:100003275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sistelligent.com"; classtype:trojan-activity; sid:100003276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skare.net"; classtype:trojan-activity; sid:100003277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyflyfares.com"; classtype:trojan-activity; sid:100003278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyscan.com"; classtype:trojan-activity; sid:100003279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smarthouseforum.ru"; classtype:trojan-activity; sid:100003280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smartzedu.com"; classtype:trojan-activity; sid:100003281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smokesolutionindia.com"; classtype:trojan-activity; sid:100003282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smritiphotography.in"; classtype:trojan-activity; sid:100003283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sobariko.com"; classtype:trojan-activity; sid:100003284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sobethuacademy.com"; classtype:trojan-activity; sid:100003285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.110route.com"; classtype:trojan-activity; sid:100003286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.officelabo.net"; classtype:trojan-activity; sid:100003287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"softanis.net"; classtype:trojan-activity; sid:100003288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sogecoenergy.com"; classtype:trojan-activity; sid:100003289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sohs.conceptechs.info"; classtype:trojan-activity; sid:100003290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"solar.amazingtribe.lk"; classtype:trojan-activity; sid:100003291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somcorbera.cat"; classtype:trojan-activity; sid:100003292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somir.com.mx"; classtype:trojan-activity; sid:100003293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soralapps.com"; classtype:trojan-activity; sid:100003294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sota-france.fr"; classtype:trojan-activity; sid:100003295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"space.proactint.org"; classtype:trojan-activity; sid:100003296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spaceframe.mobi.space-frame.co.za"; classtype:trojan-activity; sid:100003297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"special-key.cf"; classtype:trojan-activity; sid:100003298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spent.com.pl"; classtype:trojan-activity; sid:100003299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spetsesyachtcharter.gr"; classtype:trojan-activity; sid:100003300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spititourism.com"; classtype:trojan-activity; sid:100003301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spittinfire.com"; classtype:trojan-activity; sid:100003302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sports-net.de"; classtype:trojan-activity; sid:100003303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"src1.minibai.com"; classtype:trojan-activity; sid:100003304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sreenivasapaintingworks.com"; classtype:trojan-activity; sid:100003305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sriglobalit.com"; classtype:trojan-activity; sid:100003306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"srilankamovies.com"; classtype:trojan-activity; sid:100003307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"srvmanos.no-ip.info"; classtype:trojan-activity; sid:100003308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ss.monita.co.id"; classtype:trojan-activity; sid:100003309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"st.devcodin.com"; classtype:trojan-activity; sid:100003310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"staging.apparelpunch.com"; classtype:trojan-activity; sid:100003311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"starcountry.net"; classtype:trojan-activity; sid:100003312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"static.3001.net"; classtype:trojan-activity; sid:100003313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stiau.iuc.ac"; classtype:trojan-activity; sid:100003314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sticker.jewsjuice.com"; classtype:trojan-activity; sid:100003315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stiepancasetia.ac.id"; classtype:trojan-activity; sid:100003316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stlukesohag.com"; classtype:trojan-activity; sid:100003317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"store.ericalgarin.com"; classtype:trojan-activity; sid:100003318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stott-thompson.co.uk"; classtype:trojan-activity; sid:100003319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"streetdemo.yourpageserver.com"; classtype:trojan-activity; sid:100003320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"suboldesign.com"; classtype:trojan-activity; sid:100003321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sumerians.org"; classtype:trojan-activity; sid:100003322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunaryem.com.tr"; classtype:trojan-activity; sid:100003323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunbrero.com.au"; classtype:trojan-activity; sid:100003324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunmarkholidays.com"; classtype:trojan-activity; sid:100003325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"supermercadostia.com"; classtype:trojan-activity; sid:100003326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support-4-free.com"; classtype:trojan-activity; sid:100003327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support.clz.kr"; classtype:trojan-activity; sid:100003328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"supportit.online"; classtype:trojan-activity; sid:100003329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sw.yourpageserver.com"; classtype:trojan-activity; sid:100003330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweaty.dk"; classtype:trojan-activity; sid:100003331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweet-diet.com"; classtype:trojan-activity; sid:100003332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swiftlogisticseg.com"; classtype:trojan-activity; sid:100003333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swwbia.com"; classtype:trojan-activity; sid:100003334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"syracusecoffee.com"; classtype:trojan-activity; sid:100003335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sytraders.co"; classtype:trojan-activity; sid:100003336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"t.honker.info"; classtype:trojan-activity; sid:100003337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"t.netcatkit.com"; classtype:trojan-activity; sid:100003338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tacticohosting.com"; classtype:trojan-activity; sid:100003339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tadoo.ca"; classtype:trojan-activity; sid:100003340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tafsantoursandtravels.com"; classtype:trojan-activity; sid:100003341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tajushariya.com"; classtype:trojan-activity; sid:100003342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tallyinvoicecustomization.com"; classtype:trojan-activity; sid:100003343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taltus.co.uk"; classtype:trojan-activity; sid:100003344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tapalkoedacoffee.com"; classtype:trojan-activity; sid:100003345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tarravalleyfoods.com.au"; classtype:trojan-activity; sid:100003346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taurus.ug"; classtype:trojan-activity; sid:100003347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tavo.cl"; classtype:trojan-activity; sid:100003348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taxicabsrilanka.com"; classtype:trojan-activity; sid:100003349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tc.snpsresidential.com"; classtype:trojan-activity; sid:100003350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tcy.198424.com"; classtype:trojan-activity; sid:100003351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tdsp.yngw518.com"; classtype:trojan-activity; sid:100003352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tech332.synology.me"; classtype:trojan-activity; sid:100003353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"techgms.com"; classtype:trojan-activity; sid:100003354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teduae.com"; classtype:trojan-activity; sid:100003355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teleargentina.com"; classtype:trojan-activity; sid:100003356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"telescopelms.com"; classtype:trojan-activity; sid:100003357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tencoconsulting.com"; classtype:trojan-activity; sid:100003358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teneth.co.za"; classtype:trojan-activity; sid:100003359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tentandoserfitness.000webhostapp.com"; classtype:trojan-activity; sid:100003360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tessrobins.com"; classtype:trojan-activity; sid:100003361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.adventser.com"; classtype:trojan-activity; sid:100003362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.letraele.es"; classtype:trojan-activity; sid:100003363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.lubrico.in"; classtype:trojan-activity; sid:100003364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.typoten.com"; classtype:trojan-activity; sid:100003365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.wanepghana.org"; classtype:trojan-activity; sid:100003366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.asistencia247.com"; classtype:trojan-activity; sid:100003367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.tenplusone.my"; classtype:trojan-activity; sid:100003368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.basis-web.com"; classtype:trojan-activity; sid:100003369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.marrenconstruction.ie"; classtype:trojan-activity; sid:100003370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.clickitsolutionsmw.com"; classtype:trojan-activity; sid:100003371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.thinkingcorp.in"; classtype:trojan-activity; sid:100003372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testnew.yourpageserver.com"; classtype:trojan-activity; sid:100003373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testuat.itmoregistry.com"; classtype:trojan-activity; sid:100003374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teteaffiche.stephanebillon.com"; classtype:trojan-activity; sid:100003375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tewoerd.eu"; classtype:trojan-activity; sid:100003376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"textile.softberg.ro"; classtype:trojan-activity; sid:100003377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tharringtonsponsorship.com"; classtype:trojan-activity; sid:100003378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theatretalkies.in"; classtype:trojan-activity; sid:100003379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecleaningladiespdx.com"; classtype:trojan-activity; sid:100003380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecreativecafe.co.uk"; classtype:trojan-activity; sid:100003381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thedesertship.com"; classtype:trojan-activity; sid:100003382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thediasporianexperience.com"; classtype:trojan-activity; sid:100003383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thefirmlawgroup.com.au"; classtype:trojan-activity; sid:100003384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thefuturelife.in"; classtype:trojan-activity; sid:100003385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thehighlightinterior.com"; classtype:trojan-activity; sid:100003386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thekassia.co.uk"; classtype:trojan-activity; sid:100003387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"themansionkasauli.com"; classtype:trojan-activity; sid:100003388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theprofinn.com"; classtype:trojan-activity; sid:100003389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thesummitpc.net"; classtype:trojan-activity; sid:100003390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theurbantutors.com"; classtype:trojan-activity; sid:100003391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thientu.net"; classtype:trojan-activity; sid:100003392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thosewebbs.com"; classtype:trojan-activity; sid:100003393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thriveink.com"; classtype:trojan-activity; sid:100003394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tianangdep.com"; classtype:trojan-activity; sid:100003395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickfoods.tickme.lk"; classtype:trojan-activity; sid:100003396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tienda.ventadigital.com.ar"; classtype:trojan-activity; sid:100003397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"timamollo.co.za"; classtype:trojan-activity; sid:100003398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"timegonebuy.com"; classtype:trojan-activity; sid:100003399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tksb.net"; classtype:trojan-activity; sid:100003400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tlcc.com.gt"; classtype:trojan-activity; sid:100003401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tntmedia.gr"; classtype:trojan-activity; sid:100003402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"todoapp.cstdevs.com"; classtype:trojan-activity; sid:100003403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"todocontodo.com.mx"; classtype:trojan-activity; sid:100003404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonydong.com"; classtype:trojan-activity; sid:100003405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonystram.com"; classtype:trojan-activity; sid:100003406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonyzone.com"; classtype:trojan-activity; sid:100003407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tooba.tenplusone.my"; classtype:trojan-activity; sid:100003408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tools.reimclub.com"; classtype:trojan-activity; sid:100003409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topcell9.com"; classtype:trojan-activity; sid:100003410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toplevel.com.br"; classtype:trojan-activity; sid:100003411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topmask.co.za"; classtype:trojan-activity; sid:100003412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"torresquinterocorp.com"; classtype:trojan-activity; sid:100003413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toyotacollege.ac.th"; classtype:trojan-activity; sid:100003414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpef.lsoftdemo.com"; classtype:trojan-activity; sid:100003415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpke.hu"; classtype:trojan-activity; sid:100003416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"translaterjemah.com"; classtype:trojan-activity; sid:100003417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"travelwithmanta.co.za"; classtype:trojan-activity; sid:100003418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trendyshoes.co.za"; classtype:trojan-activity; sid:100003419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trezors.io.mahlongwa.com"; classtype:trojan-activity; sid:100003420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trimestre.bar"; classtype:trojan-activity; sid:100003421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"triplonet.com.br"; classtype:trojan-activity; sid:100003422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"troki.com.co"; classtype:trojan-activity; sid:100003423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tropics.codeleek.net"; classtype:trojan-activity; sid:100003424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trudelfavreau.com"; classtype:trojan-activity; sid:100003425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tsd.jxwan.com"; classtype:trojan-activity; sid:100003426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tulli.info"; classtype:trojan-activity; sid:100003427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tupperware.michaelroberge.ca"; classtype:trojan-activity; sid:100003428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"turanggaresources.com"; classtype:trojan-activity; sid:100003429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"txtdust.com"; classtype:trojan-activity; sid:100003430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uat.indianfilmzone.com"; classtype:trojan-activity; sid:100003431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ublretailerdemo.cstdevs.com"; classtype:trojan-activity; sid:100003432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uc-56.ru"; classtype:trojan-activity; sid:100003433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uisusa.uisusa.com"; classtype:trojan-activity; sid:100003434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ultimate-24.de"; classtype:trojan-activity; sid:100003435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"umwelt-kirchhof.de"; classtype:trojan-activity; sid:100003436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unicorpbrunei.com"; classtype:trojan-activity; sid:100003437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uniengrisb.com"; classtype:trojan-activity; sid:100003438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unyazitelecom.com"; classtype:trojan-activity; sid:100003439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"upcbpta.com"; classtype:trojan-activity; sid:100003440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"urbantrapfest.cl"; classtype:trojan-activity; sid:100003441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"usamyforever.azureedge.net"; classtype:trojan-activity; sid:100003442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"used-jeans.fr"; classtype:trojan-activity; sid:100003443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"useformoney.000webhostapp.com"; classtype:trojan-activity; sid:100003444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"usmadetshirts.com"; classtype:trojan-activity; sid:100003445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uss.ac.th"; classtype:trojan-activity; sid:100003446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uzzepay.com.br"; classtype:trojan-activity; sid:100003447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vanzare.cabanabrazi2.ro"; classtype:trojan-activity; sid:100003448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vbcargo.hu"; classtype:trojan-activity; sid:100003449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vcah.co.uk"; classtype:trojan-activity; sid:100003450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vectarts.com"; classtype:trojan-activity; sid:100003451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vegadelcasero.cl"; classtype:trojan-activity; sid:100003452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vendas.lidiacarmeli.com.br"; classtype:trojan-activity; sid:100003453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"veterinariadrpopui.com"; classtype:trojan-activity; sid:100003454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vfocus.net"; classtype:trojan-activity; sid:100003455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vienen.gblix.srv.br"; classtype:trojan-activity; sid:100003456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vilaart.rs"; classtype:trojan-activity; sid:100003457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villamarand.com"; classtype:trojan-activity; sid:100003458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villatera.com"; classtype:trojan-activity; sid:100003459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"violinstop.com"; classtype:trojan-activity; sid:100003460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"virtuleverage.com"; classtype:trojan-activity; sid:100003461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visions.alnisamart.com"; classtype:trojan-activity; sid:100003462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visualhome.cl"; classtype:trojan-activity; sid:100003463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vitoriamodaintima.com.br"; classtype:trojan-activity; sid:100003464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vivationdesign.com"; classtype:trojan-activity; sid:100003465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"viveirodoiscorregos.com.br"; classtype:trojan-activity; sid:100003466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vksales.com"; classtype:trojan-activity; sid:100003467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vocalterra.com"; classtype:trojan-activity; sid:100003468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vokasi.ub.ac.id"; classtype:trojan-activity; sid:100003469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vologroup.com.br"; classtype:trojan-activity; sid:100003470; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"voteyouramerica.dekitout.com"; classtype:trojan-activity; sid:100003471; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vpinversiones.cl"; classtype:trojan-activity; sid:100003472; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vpts.co.za"; classtype:trojan-activity; sid:100003473; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vstsample.com"; classtype:trojan-activity; sid:100003474; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vtube.fadlymotivator.com"; classtype:trojan-activity; sid:100003475; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vvsskmodinationalschool.com"; classtype:trojan-activity; sid:100003476; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu"; classtype:trojan-activity; sid:100003477; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepliberia.org"; classtype:trojan-activity; sid:100003478; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepniger.org"; classtype:trojan-activity; sid:100003479; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.eng.ubu.ac.th"; classtype:trojan-activity; sid:100003480; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.geetle.ga"; classtype:trojan-activity; sid:100003481; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.geomegasoft.net"; classtype:trojan-activity; sid:100003482; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.newinnovationtechnology.com"; classtype:trojan-activity; sid:100003483; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.smarts-works.com"; classtype:trojan-activity; sid:100003484; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.thebeessolution.com"; classtype:trojan-activity; sid:100003485; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webgis.perumdasolo.com"; classtype:trojan-activity; sid:100003486; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webmailwindstreamnetmessagesecureapp1rqr.ga"; classtype:trojan-activity; sid:100003487; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webpresario.com"; classtype:trojan-activity; sid:100003488; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"website-work.com"; classtype:trojan-activity; sid:100003489; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weinsteincounseling.com"; classtype:trojan-activity; sid:100003490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wfinance.com.br"; classtype:trojan-activity; sid:100003491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whcms.yourpageserver.com"; classtype:trojan-activity; sid:100003492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whiteresponse.com"; classtype:trojan-activity; sid:100003493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wi522012.ferozo.com"; classtype:trojan-activity; sid:100003494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wikalen.co.za"; classtype:trojan-activity; sid:100003495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildnights.co.uk"; classtype:trojan-activity; sid:100003496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildtrust.mediadevstaging.com"; classtype:trojan-activity; sid:100003497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"willow-nettica.com"; classtype:trojan-activity; sid:100003498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wimbamusica.com"; classtype:trojan-activity; sid:100003499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"windcomtechnologies.com"; classtype:trojan-activity; sid:100003500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wishesconcierge.com"; classtype:trojan-activity; sid:100003501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woezon.agency"; classtype:trojan-activity; sid:100003502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wolfgang-brodte.de"; classtype:trojan-activity; sid:100003503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wonderhawaii.com"; classtype:trojan-activity; sid:100003504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woodsytech.com"; classtype:trojan-activity; sid:100003505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wordpress.saleensuporte.com.br"; classtype:trojan-activity; sid:100003506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wozata.000webhostapp.com"; classtype:trojan-activity; sid:100003507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wp.readhere.in"; classtype:trojan-activity; sid:100003508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wpdemo.101clients.com.au"; classtype:trojan-activity; sid:100003509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"writtendeer.com"; classtype:trojan-activity; sid:100003510; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ws5588.f3322.net"; classtype:trojan-activity; sid:100003511; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wsdyrmtcntlfarmtwsvb.dns.army"; classtype:trojan-activity; sid:100003512; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wyklej.pl"; classtype:trojan-activity; sid:100003513; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"x-iting.de"; classtype:trojan-activity; sid:100003514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"x2vn.com"; classtype:trojan-activity; sid:100003515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xia.beihaixue.com"; classtype:trojan-activity; sid:100003516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xixaoclothing.com"; classtype:trojan-activity; sid:100003517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xk.996is.com"; classtype:trojan-activity; sid:100003518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--80akinnkiib6h.xn--90ais"; classtype:trojan-activity; sid:100003519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--polimerbizmimarlk-rvc.com"; classtype:trojan-activity; sid:100003520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ybom.urbanolab.com"; classtype:trojan-activity; sid:100003521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yeichner.com"; classtype:trojan-activity; sid:100003522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ylfpremium.com"; classtype:trojan-activity; sid:100003523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yoast.yourpageserver.com"; classtype:trojan-activity; sid:100003524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yourclub1.com"; classtype:trojan-activity; sid:100003525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yourtopdog.com.au"; classtype:trojan-activity; sid:100003526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"youtubetrainingacademy.com"; classtype:trojan-activity; sid:100003527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yp.hnggzyjy.cn"; classtype:trojan-activity; sid:100003528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yskadvisors.com"; classtype:trojan-activity; sid:100003529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yummyyogaudaipur.com"; classtype:trojan-activity; sid:100003530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yzkzixun.com"; classtype:trojan-activity; sid:100003531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zmedcoach.com"; classtype:trojan-activity; sid:100003532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zytrox.tk"; classtype:trojan-activity; sid:100003533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zz.690tx.com"; classtype:trojan-activity; sid:100003534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100003535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/86.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100003536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c64.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100003537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; endswith; nocase; http.host; content:"amumufree.weebly.com"; classtype:trojan-activity; sid:100003538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/proxyi.exe"; endswith; nocase; http.host; content:"analogx.com"; classtype:trojan-activity; sid:100003539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvdfv/anjj/downloads/jami.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/johnhast/efve/downloads/versiumr.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/johnhast/efve/downloads/versiumrr.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/4.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/6.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labesoftware/update/downloads/boost-fps.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labesoftware/update/downloads/install_plugin_x64_x86.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labesoftware/update/downloads/vpn_free.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/clr.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatev.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/work.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/component.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/regsvc.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skygaming/updates/downloads/update.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/001.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1488.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1_cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1fc2d.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/26a5.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/abjects.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/attached.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/b7f2c.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/battletext.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_makros.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_silent.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_sup.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildss.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientnik.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientrevers.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dcrat.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hans.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hulu.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfive.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfour.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelone.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelthree.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/inteltwo.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/kleiman.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/notepadplus.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/putty.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/rockethcd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/scvhost900.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/sessionwin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/siliculose.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/statemobi.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stgedo.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/svcperf.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurjok.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurusbabac.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/telekiller.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateanddr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateandr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/vhajeja.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/word.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/www.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/xlsd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hmatrix/data/hack1226.exe"; endswith; nocase; http.host; content:"cd.textfiles.com"; classtype:trojan-activity; sid:100003620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/816070119281131570/816070273254162442/all.txt"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/825372018244583454/826848185246023750/loaddd.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/825372018244583454/826848348342059008/zeppelin.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/825372018244583454/826848405258633277/build.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/826198252025675816/826537386485612574/china.png"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/razor/rzr-winner_intro.zip"; endswith; nocase; http.host; content:"chiptune.com"; classtype:trojan-activity; sid:100003629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100003630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100003631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meteoradminz/hidden-tear/zip/master"; endswith; nocase; http.host; content:"codeload.github.com"; classtype:trojan-activity; sid:100003632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; endswith; nocase; http.host; content:"colfincas.com"; classtype:trojan-activity; sid:100003633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qz0h69.pdf"; endswith; nocase; http.host; content:"deepfreedom.org"; classtype:trojan-activity; sid:100003634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ktcghnmcwws43wzscphukbfnwtuaxidx&revid=0b8z0b7_i5sirk2xrtehmstg0vxvit3b4n3lmbdrdrjrodndrpq"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100003635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; endswith; nocase; http.host; content:"drive.google.com.it-barcelona.com"; classtype:trojan-activity; sid:100003636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=12khl-unz2np4q54b2jgpwlsh6cuz0pss"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=13sfskplrox3d7uantwjj_trs6ciwvqa1"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=152yoztzpbx_bbpxepfackfklg8c1eao6"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=15hcgek7odccdafzf-9gvibnlgkirj4uo"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=194lqzukzvt-jtdxmihcvhd0yk1sxoybk"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1br5iufkkmmfeipqo3ecviqykbcdgcnio"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1cos43rmscrescxk3u40qjuqbwr-pydsn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1dhoxtwbb2ycn8q06gi3p-ao_llldff0e"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1dnm3wtjf6ud5fv6zop9cvbr4rs2of1-n"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1dqin1sdd6rbah3sggzsxzeqgrkmhjnqm"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1fensc6gc0fww0gbevsrnwwnlajypzdvv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1htinwtfrw1wc3_ma8odztnq0qpnic2q6"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1jkov2g5s1xkcq4bfb3uvmd6inhadatrg"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1jnarxelz8gtbkg5pa_s0rc8kv3ejkepn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1kjcylye1dbmhystyyotz-3pagktkhlhq"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1lsv4sko083sywwjndgqnsh_6sgqodqtu"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1mwgdd3lxuuk-bnsrm1rpclom0cmx7wob"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1nmf6kty3xsoygjxjhb-bsafvlfy-0lt2"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1p5fvqkxzwoiu_uauzbmrxpklsetculad"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1q1dwckludrpqijtrpw14_60d5nu7n97t"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1r9f9irwhutxozsbp2h9erd_a7fa2pwko"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1s221a6wpx6i7nfrztnhh9priojtybuxq"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1sjvkrinuscxqmbkdeusxaezazbiagnv3"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1so1trfuzt5-giahetghfhmd-_ot3rq35"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1uowridpynurgqlgqjbtgramigo2a9v76"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vjq92eqivh01yxmal20whl2es3ld6nxb"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yqpuxjbnjokc5fjgt-8xzuybr97rtvg2"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ywkgalidldb32pio6ywmbyvdk7oar3yy"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/1zilg/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100003691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/qcgfmfvh/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100003692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/emclick.zip"; endswith; nocase; http.host; content:"e-mudhra.com"; classtype:trojan-activity; sid:100003693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100003694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100003695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100003696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; endswith; nocase; http.host; content:"file.elecfans.com"; classtype:trojan-activity; sid:100003701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100003702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100003703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; endswith; nocase; http.host; content:"gist.githubusercontent.com"; classtype:trojan-activity; sid:100003704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; endswith; nocase; http.host; content:"hqdecig.com"; classtype:trojan-activity; sid:100003705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/suy/"; endswith; nocase; http.host; content:"hsecaravans.co.uk"; classtype:trojan-activity; sid:100003706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19/items/startup_20210219/startup.txt"; endswith; nocase; http.host; content:"ia801802.us.archive.org"; classtype:trojan-activity; sid:100003707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/online-timer-kvhxz/ilxl/"; endswith; nocase; http.host; content:"ie-best.net"; classtype:trojan-activity; sid:100003708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100003709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100003710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ebook/cs17.exe"; endswith; nocase; http.host; content:"jcedu.org"; classtype:trojan-activity; sid:100003711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100003712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100003713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100003714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; endswith; nocase; http.host; content:"karmakoincodes.weebly.com"; classtype:trojan-activity; sid:100003715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dg/etrac/nf4emwz/"; endswith; nocase; http.host; content:"kotakwarna.co.id"; classtype:trojan-activity; sid:100003716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe"; endswith; nocase; http.host; content:"ksh.hu"; classtype:trojan-activity; sid:100003717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/affiliate/kuaizip_setup_10029.exe"; endswith; nocase; http.host; content:"kuaizip.com"; classtype:trojan-activity; sid:100003718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linuxforensicscode.zip"; endswith; nocase; http.host; content:"linuxforensicsbook.com.s3.amazonaws.com"; classtype:trojan-activity; sid:100003719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k/big5/1giof6/"; endswith; nocase; http.host; content:"minpic.de"; classtype:trojan-activity; sid:100003720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; endswith; nocase; http.host; content:"my.cloudme.com"; classtype:trojan-activity; sid:100003721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/aacenc.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100003722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/doxillionsetup.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100003723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/4/1/6/6/4166984/keygen.exe"; endswith; nocase; http.host; content:"newyarlfm.weebly.com"; classtype:trojan-activity; sid:100003724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; endswith; nocase; http.host; content:"nhipcauytevietnhat.com"; classtype:trojan-activity; sid:100003725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; endswith; nocase; http.host; content:"note.youdao.com"; classtype:trojan-activity; sid:100003726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; endswith; nocase; http.host; content:"oldschoolvalue.s3.amazonaws.com"; classtype:trojan-activity; sid:100003727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21108&authkey=acq44gahejhwrag"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=032ce380af7ab389&resid=32ce380af7ab389!210&authkey=akcynbtc0h3ui7e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=032ce380af7ab389&resid=32ce380af7ab389%21210&authkey=akcynbtc0h3ui7e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d!184&authkey=ackbiiarirejcam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d%21184&authkey=ackbiiarirejcam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0!1667&authkey=an8otd7jzc7xgho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0%211667&authkey=an8otd7jzc7xgho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0da4ace18aa7d1e2&resid=da4ace18aa7d1e2%21131&authkey=adjn1y5pp4a10_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f!286&authkey=almwisomhv3c0zc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!140&authkey=apn44x6bxlzq3ac"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!151&authkey=aeuk7knodrpenek"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!153&authkey=ao6e8g0bzbp_idw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!154&authkey=ah4chedbotzpmtq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!156&authkey=ajnqscnmrdonpkg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21140&authkey=apn44x6bxlzq3ac"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21151&authkey=aeuk7knodrpenek"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21153&authkey=ao6e8g0bzbp_idw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21154&authkey=ah4chedbotzpmtq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21156&authkey=ajnqscnmrdonpkg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2968c371f5450503&resid=2968c371f5450503!122&authkey=aaqhhxbnwfwrz28"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2968c371f5450503&resid=2968c371f5450503%21122&authkey=aaqhhxbnwfwrz28"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1!223&authkey=aajr842bzum0yg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3ee68228c34c236d&resid=3ee68228c34c236d%21129&authkey=apll6hu3-xetzxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba!2203&authkey=ajvalmr5l8epwvm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba%212203&authkey=ajvalmr5l8epwvm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21141&authkey=aazwaw2xjms24o0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21198&authkey=akq4jrbjm6spd9m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!109&authkey=ap-okubj9bvtlc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21106&authkey=an9dhtmtufpis-m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21109&authkey=ap-okubj9bvtlc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2!517&authkey=akfewcyiwlwomyk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21517&authkey=akfewcyiwlwomyk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!301&authkey=abquzhtdjg5pryk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!302&authkey=al2_xstzqulnnqw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!305&authkey=an-uuhplpk2zp5u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21301&authkey=abquzhtdjg5pryk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21302&authkey=al2_xstzqulnnqw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21305&authkey=an-uuhplpk2zp5u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70d8fa75c83fbdbe&resid=70d8fa75c83fbdbe%21144&authkey=acw8wl1noncfp-4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!106&authkey=ahu5s4ttjvxbnxo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!107&authkey=abj3eccentbeaqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!108&authkey=amvcygo4prlgt4i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!110&authkey=ahzuehvk5nvzo90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21106&authkey=ahu5s4ttjvxbnxo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21107&authkey=abj3eccentbeaqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21108&authkey=amvcygo4prlgt4i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21110&authkey=ahzuehvk5nvzo90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125570&authkey=aejqgjglwurnb0a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21444&authkey=abzxvycu0ggtmg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004070; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004071; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004072; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004073; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=89360b4c7415c088&resid=89360b4c7415c088%21106&authkey=akfcfq3zq5oof2i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=89360b4c7415c088&resid=89360b4c7415c088%21108&authkey=amfbkmapqbvzpvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!254&authkey=ajt5wxegbvzbwqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!255&authkey=aaimhpp89qmcfhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33%21254&authkey=ajt5wxegbvzbwqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!112&authkey=af43qpcgl0t2f5o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!305&authkey=apgh_teb3673nek"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!306&authkey=aibymhcuhqnmrwo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21305&authkey=apgh_teb3673nek"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9fb622acb27482ef&resid=9fb622acb27482ef%211197&authkey=aeacibxy2zlyxro"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a31988151cf6813e&resid=a31988151cf6813e%21107&authkey=ab9lanzt1aj_0ws"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21256&authkey=aapnly5qifymcvw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818!129&authkey=aesewk3cf5vbrxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818%21129&authkey=aesewk3cf5vbrxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1047&authkey=aod6jbxyicq2v4g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211047&authkey=aod6jbxyicq2v4g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!362&authkey=alycl9izrvfl7oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21362&authkey=alycl9izrvfl7oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cda6c13b54bbe48c&resid=cda6c13b54bbe48c!44331&authkey=afohia-wo-alwiy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cda6c13b54bbe48c&resid=cda6c13b54bbe48c%2144331&authkey=afohia-wo-alwiy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d4d413b6e7cf7088&resid=d4d413b6e7cf7088%211271&authkey=akz65bxpgvdxjb8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2!1818&authkey=anh2wga7qmhbmuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2%211818&authkey=anh2wga7qmhbmuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2!107&authkey=af-bicrg1c6vgck"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2%21107&authkey=af-bicrg1c6vgck"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e627fc797baa3032&resid=e627fc797baa3032%212324&authkey=aa8i-r7ixmcraha"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8!148&authkey=agjcwq650c8wdbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8!150&authkey=ami5aqoinvosjle"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8%21148&authkey=agjcwq650c8wdbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8%21150&authkey=ami5aqoinvosjle"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ef7cc06ce7ffafb8&resid=ef7cc06ce7ffafb8%21108&authkey=anmpeqm9gm_zv9m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!226&authkey=adho6klfkjflaqk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!229&authkey=akvo12quxgcwnk8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!234&authkey=abhyu_zfy6bhwmu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21226&authkey=adho6klfkjflaqk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21234&authkey=abhyu_zfy6bhwmu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c!115&authkey=adbcrakskolznjq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c%21115&authkey=adbcrakskolznjq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c%21116&authkey=anenotuhbsni0zu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21848&authkey=ag1_e421v-t5r9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!198&authkey=amg468jpljbyyky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21198&authkey=amg468jpljbyyky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r/a39ev"; endswith; nocase; http.host; content:"paste.ee"; classtype:trojan-activity; sid:100004349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r/oitkz"; endswith; nocase; http.host; content:"paste.ee"; classtype:trojan-activity; sid:100004350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/77jhk0iw"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100004351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/89hkc7wb"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100004352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/yqvsvlvq"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100004353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/llc/mwcacs65xienqdp/"; endswith; nocase; http.host; content:"pierreconsulting.info"; classtype:trojan-activity; sid:100004354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bayesian-forecasting-amj5e/s5hqmf6/"; endswith; nocase; http.host; content:"pioneiraagronegocio.com.br"; classtype:trojan-activity; sid:100004355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skoda22.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100004356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100004357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; endswith; nocase; http.host; content:"qjbutterflyevents.co.za"; classtype:trojan-activity; sid:100004358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dhlshipmentawb80326979402.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100004359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maersk-bl+draft-copy-shipping-documents.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100004360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/po+for+april+shipment.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100004361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zenar.exe"; endswith; nocase; http.host; content:"racisa.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100004362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myqseeaccount/one/main/one.htm"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tennc/webshell/master/other/small_shell.txt"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; endswith; nocase; http.host; content:"res.yeshen.com"; classtype:trojan-activity; sid:100004374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/q05z91"; endswith; nocase; http.host; content:"sendspace.com"; classtype:trojan-activity; sid:100004375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ey4lpx8rx.zip"; endswith; nocase; http.host; content:"shribharatvatika.com"; classtype:trojan-activity; sid:100004376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; endswith; nocase; http.host; content:"sites.google.com"; classtype:trojan-activity; sid:100004377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-nurse-ss8d9/z/"; endswith; nocase; http.host; content:"technologydistilled.com"; classtype:trojan-activity; sid:100004387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/23.exe"; endswith; nocase; http.host; content:"tsrv4.ws"; classtype:trojan-activity; sid:100004388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crisanar/defis/jek_crackme1.7.zip"; endswith; nocase; http.host; content:"users.skynet.be"; classtype:trojan-activity; sid:100004389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/amowvegfrt9ja/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100004390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100004391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100004392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100004393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb%5efr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb^fr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/151_155/tidex_-_short_stuff.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syria-files/attach/222/222051_instruction.zip"; endswith; nocase; http.host; content:"wikileaks.org"; classtype:trojan-activity; sid:100004399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.223.92"; classtype:trojan-activity; sid:100000160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.225.24"; classtype:trojan-activity; sid:100000161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.235.57"; classtype:trojan-activity; sid:100000162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.249.21"; classtype:trojan-activity; sid:100000163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.4.2"; classtype:trojan-activity; sid:100000164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110fss.net"; classtype:trojan-activity; sid:100000165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.41.173"; classtype:trojan-activity; sid:100000166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.88.61"; classtype:trojan-activity; sid:100000167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.119.245.114"; classtype:trojan-activity; sid:100000168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.125.67.125"; classtype:trojan-activity; sid:100000169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.165.21.195"; classtype:trojan-activity; sid:100000170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.166.236.191"; classtype:trojan-activity; sid:100000171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.167.151.156"; classtype:trojan-activity; sid:100000172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.85.71"; classtype:trojan-activity; sid:100000173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.86.31"; classtype:trojan-activity; sid:100000174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.172.57.20"; classtype:trojan-activity; sid:100000175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.182.235.252"; classtype:trojan-activity; sid:100000176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.171.111"; classtype:trojan-activity; sid:100000177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.177.85"; classtype:trojan-activity; sid:100000178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.23.84"; classtype:trojan-activity; sid:100000179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.230.136"; classtype:trojan-activity; sid:100000180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.27.9"; classtype:trojan-activity; sid:100000181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.49.223"; classtype:trojan-activity; sid:100000182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.122"; classtype:trojan-activity; sid:100000183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.66"; classtype:trojan-activity; sid:100000184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.104.141"; classtype:trojan-activity; sid:100000185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.104.15"; classtype:trojan-activity; sid:100000186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.19"; classtype:trojan-activity; sid:100000187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.222"; classtype:trojan-activity; sid:100000188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.223"; classtype:trojan-activity; sid:100000189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.226"; classtype:trojan-activity; sid:100000190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.228"; classtype:trojan-activity; sid:100000191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.26.243"; classtype:trojan-activity; sid:100000192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.8.81"; classtype:trojan-activity; sid:100000193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.61.52.53"; classtype:trojan-activity; sid:100000194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.108.184"; classtype:trojan-activity; sid:100000195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.133.222.151"; classtype:trojan-activity; sid:100000196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.147.92.51"; classtype:trojan-activity; sid:100000197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.159.108.96"; classtype:trojan-activity; sid:100000198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.163.200.217"; classtype:trojan-activity; sid:100000199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.124.75"; classtype:trojan-activity; sid:100000200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.210.211"; classtype:trojan-activity; sid:100000201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.96.252"; classtype:trojan-activity; sid:100000202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.187.91.117"; classtype:trojan-activity; sid:100000203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.214.127.42"; classtype:trojan-activity; sid:100000204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.187.19"; classtype:trojan-activity; sid:100000205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.236.77"; classtype:trojan-activity; sid:100000206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.239.126"; classtype:trojan-activity; sid:100000207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.43.27"; classtype:trojan-activity; sid:100000208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.118.229"; classtype:trojan-activity; sid:100000209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.202.111"; classtype:trojan-activity; sid:100000210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.67.193"; classtype:trojan-activity; sid:100000211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.180.95"; classtype:trojan-activity; sid:100000212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.79.114"; classtype:trojan-activity; sid:100000213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.79.137"; classtype:trojan-activity; sid:100000214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.178.109"; classtype:trojan-activity; sid:100000215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.188.28"; classtype:trojan-activity; sid:100000216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.230.168.103"; classtype:trojan-activity; sid:100000217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.218.202"; classtype:trojan-activity; sid:100000218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.235.149.73"; classtype:trojan-activity; sid:100000219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.235.188.86"; classtype:trojan-activity; sid:100000220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.171.69"; classtype:trojan-activity; sid:100000221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.141.241"; classtype:trojan-activity; sid:100000222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.144.226"; classtype:trojan-activity; sid:100000223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.197.144"; classtype:trojan-activity; sid:100000224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.209.30"; classtype:trojan-activity; sid:100000225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.75.157"; classtype:trojan-activity; sid:100000226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.143.135"; classtype:trojan-activity; sid:100000227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.17.120"; classtype:trojan-activity; sid:100000228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.190.207"; classtype:trojan-activity; sid:100000229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.227.228"; classtype:trojan-activity; sid:100000230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.39.2"; classtype:trojan-activity; sid:100000231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.73.181"; classtype:trojan-activity; sid:100000232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.240.216.17"; classtype:trojan-activity; sid:100000233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.152.44"; classtype:trojan-activity; sid:100000234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.2.247"; classtype:trojan-activity; sid:100000235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.243.80"; classtype:trojan-activity; sid:100000236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.12.89"; classtype:trojan-activity; sid:100000237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.8.24"; classtype:trojan-activity; sid:100000238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.126.58"; classtype:trojan-activity; sid:100000239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.162.50"; classtype:trojan-activity; sid:100000240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.180.49"; classtype:trojan-activity; sid:100000241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.51.77"; classtype:trojan-activity; sid:100000242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.100.14"; classtype:trojan-activity; sid:100000243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.121.39"; classtype:trojan-activity; sid:100000244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.16.222"; classtype:trojan-activity; sid:100000245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.191.118"; classtype:trojan-activity; sid:100000246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.214.146"; classtype:trojan-activity; sid:100000247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.240.226"; classtype:trojan-activity; sid:100000248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.25.42"; classtype:trojan-activity; sid:100000249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.8.112"; classtype:trojan-activity; sid:100000250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.81.173"; classtype:trojan-activity; sid:100000251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.82.122"; classtype:trojan-activity; sid:100000252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.148.90"; classtype:trojan-activity; sid:100000253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.197.164"; classtype:trojan-activity; sid:100000254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.109.217"; classtype:trojan-activity; sid:100000255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.118.157"; classtype:trojan-activity; sid:100000256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.26.129"; classtype:trojan-activity; sid:100000257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.79.98"; classtype:trojan-activity; sid:100000258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.250.102.173"; classtype:trojan-activity; sid:100000259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.218.210"; classtype:trojan-activity; sid:100000260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.136.84"; classtype:trojan-activity; sid:100000261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.196.17"; classtype:trojan-activity; sid:100000262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.221.244"; classtype:trojan-activity; sid:100000263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.239.103"; classtype:trojan-activity; sid:100000264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.254.208.123"; classtype:trojan-activity; sid:100000265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.254.32.5"; classtype:trojan-activity; sid:100000266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.38.10"; classtype:trojan-activity; sid:100000267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.6.129"; classtype:trojan-activity; sid:100000268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.8.235"; classtype:trojan-activity; sid:100000269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.121.163"; classtype:trojan-activity; sid:100000270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.108"; classtype:trojan-activity; sid:100000271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.111"; classtype:trojan-activity; sid:100000272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.117"; classtype:trojan-activity; sid:100000273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.122"; classtype:trojan-activity; sid:100000274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.124"; classtype:trojan-activity; sid:100000275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.131"; classtype:trojan-activity; sid:100000276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.132"; classtype:trojan-activity; sid:100000277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.133"; classtype:trojan-activity; sid:100000278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.138"; classtype:trojan-activity; sid:100000279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.139"; classtype:trojan-activity; sid:100000280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.142"; classtype:trojan-activity; sid:100000281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.143"; classtype:trojan-activity; sid:100000282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.146"; classtype:trojan-activity; sid:100000283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.149"; classtype:trojan-activity; sid:100000284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.150"; classtype:trojan-activity; sid:100000285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.151"; classtype:trojan-activity; sid:100000286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.158"; classtype:trojan-activity; sid:100000287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.160"; classtype:trojan-activity; sid:100000288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.162"; classtype:trojan-activity; sid:100000289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.163"; classtype:trojan-activity; sid:100000290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.165"; classtype:trojan-activity; sid:100000291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.171"; classtype:trojan-activity; sid:100000292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.174"; classtype:trojan-activity; sid:100000293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.175"; classtype:trojan-activity; sid:100000294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.177"; classtype:trojan-activity; sid:100000295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.178"; classtype:trojan-activity; sid:100000296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.179"; classtype:trojan-activity; sid:100000297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.127.155"; classtype:trojan-activity; sid:100000298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.182"; classtype:trojan-activity; sid:100000299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.23"; classtype:trojan-activity; sid:100000300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.85.113"; classtype:trojan-activity; sid:100000301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.87.213"; classtype:trojan-activity; sid:100000302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.88.116"; classtype:trojan-activity; sid:100000303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.91.212"; classtype:trojan-activity; sid:100000304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.133"; classtype:trojan-activity; sid:100000305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.158"; classtype:trojan-activity; sid:100000306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.164"; classtype:trojan-activity; sid:100000307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.168"; classtype:trojan-activity; sid:100000308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.177"; classtype:trojan-activity; sid:100000309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.188"; classtype:trojan-activity; sid:100000310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.190"; classtype:trojan-activity; sid:100000311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.211"; classtype:trojan-activity; sid:100000312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.219"; classtype:trojan-activity; sid:100000313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.229"; classtype:trojan-activity; sid:100000314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.230"; classtype:trojan-activity; sid:100000315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.247"; classtype:trojan-activity; sid:100000316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.57"; classtype:trojan-activity; sid:100000317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.90"; classtype:trojan-activity; sid:100000318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.91"; classtype:trojan-activity; sid:100000319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.31"; classtype:trojan-activity; sid:100000320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.36"; classtype:trojan-activity; sid:100000321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.38"; classtype:trojan-activity; sid:100000322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.41"; classtype:trojan-activity; sid:100000323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.43"; classtype:trojan-activity; sid:100000324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.48"; classtype:trojan-activity; sid:100000325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.52"; classtype:trojan-activity; sid:100000326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.35.237"; classtype:trojan-activity; sid:100000327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.38.98"; classtype:trojan-activity; sid:100000328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.103"; classtype:trojan-activity; sid:100000329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.118"; classtype:trojan-activity; sid:100000330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.121"; classtype:trojan-activity; sid:100000331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.124"; classtype:trojan-activity; sid:100000332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.136"; classtype:trojan-activity; sid:100000333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.52"; classtype:trojan-activity; sid:100000334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.240.239"; classtype:trojan-activity; sid:100000335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.87.98"; classtype:trojan-activity; sid:100000336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.224.79"; classtype:trojan-activity; sid:100000337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.65.53.175"; classtype:trojan-activity; sid:100000338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.153.37"; classtype:trojan-activity; sid:100000339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.159"; classtype:trojan-activity; sid:100000340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.49"; classtype:trojan-activity; sid:100000341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.53"; classtype:trojan-activity; sid:100000342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.112"; classtype:trojan-activity; sid:100000343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.84"; classtype:trojan-activity; sid:100000344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.226.202"; classtype:trojan-activity; sid:100000345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.78.45.158"; classtype:trojan-activity; sid:100000346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.117.32"; classtype:trojan-activity; sid:100000347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.118.16"; classtype:trojan-activity; sid:100000348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.127.91"; classtype:trojan-activity; sid:100000349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.207.144"; classtype:trojan-activity; sid:100000350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.215.101"; classtype:trojan-activity; sid:100000351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.218.56"; classtype:trojan-activity; sid:100000352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.146.253"; classtype:trojan-activity; sid:100000353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.18.255"; classtype:trojan-activity; sid:100000354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.224.139"; classtype:trojan-activity; sid:100000355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.93.29.211"; classtype:trojan-activity; sid:100000356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.11.95.254"; classtype:trojan-activity; sid:100000357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.144.140"; classtype:trojan-activity; sid:100000358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.122.238.68"; classtype:trojan-activity; sid:100000359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.161.58.249"; classtype:trojan-activity; sid:100000360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.161.78.185"; classtype:trojan-activity; sid:100000361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.172.250.35"; classtype:trojan-activity; sid:100000362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.195.163.26"; classtype:trojan-activity; sid:100000363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.226.42.250"; classtype:trojan-activity; sid:100000364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.194.172"; classtype:trojan-activity; sid:100000365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.35.229"; classtype:trojan-activity; sid:100000366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.211.131"; classtype:trojan-activity; sid:100000367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.254.169.251"; classtype:trojan-activity; sid:100000368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.128.133"; classtype:trojan-activity; sid:100000369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.133.16"; classtype:trojan-activity; sid:100000370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.154.21"; classtype:trojan-activity; sid:100000371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.191.47"; classtype:trojan-activity; sid:100000372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.61.204.205"; classtype:trojan-activity; sid:100000373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.89.43.185"; classtype:trojan-activity; sid:100000374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.90.26.136"; classtype:trojan-activity; sid:100000375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.111.242.3"; classtype:trojan-activity; sid:100000376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.199.253.235"; classtype:trojan-activity; sid:100000377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.200.154.181"; classtype:trojan-activity; sid:100000378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.224.203.128"; classtype:trojan-activity; sid:100000379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.226.100.56"; classtype:trojan-activity; sid:100000380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.228.205.101"; classtype:trojan-activity; sid:100000381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.229.165.194"; classtype:trojan-activity; sid:100000382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.235.115.236"; classtype:trojan-activity; sid:100000383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.30.54.64"; classtype:trojan-activity; sid:100000384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.79.172.42"; classtype:trojan-activity; sid:100000385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.165.216.112"; classtype:trojan-activity; sid:100000386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.201.38.185"; classtype:trojan-activity; sid:100000387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.42.47.36"; classtype:trojan-activity; sid:100000388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.21.56"; classtype:trojan-activity; sid:100000389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.125.55"; classtype:trojan-activity; sid:100000390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.18.65"; classtype:trojan-activity; sid:100000391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.153.194"; classtype:trojan-activity; sid:100000392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.60.129"; classtype:trojan-activity; sid:100000393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.131.242"; classtype:trojan-activity; sid:100000394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.133.96"; classtype:trojan-activity; sid:100000395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.144.213"; classtype:trojan-activity; sid:100000396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.159.132"; classtype:trojan-activity; sid:100000397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.132.140"; classtype:trojan-activity; sid:100000398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.165.147"; classtype:trojan-activity; sid:100000399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.255.194"; classtype:trojan-activity; sid:100000400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.118.201"; classtype:trojan-activity; sid:100000401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.69.102.84"; classtype:trojan-activity; sid:100000402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.73.3.11"; classtype:trojan-activity; sid:100000403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.92.174.231"; classtype:trojan-activity; sid:100000404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.124.219.2"; classtype:trojan-activity; sid:100000405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.132.151.60"; classtype:trojan-activity; sid:100000406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.206.164.46"; classtype:trojan-activity; sid:100000407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.211.100.26"; classtype:trojan-activity; sid:100000408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.212.132.119"; classtype:trojan-activity; sid:100000409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.212.142.215"; classtype:trojan-activity; sid:100000410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.166.219"; classtype:trojan-activity; sid:100000411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.196.50.107"; classtype:trojan-activity; sid:100000412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.138"; classtype:trojan-activity; sid:100000413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.5"; classtype:trojan-activity; sid:100000414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.210.52"; classtype:trojan-activity; sid:100000415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.220.126"; classtype:trojan-activity; sid:100000416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.236.14"; classtype:trojan-activity; sid:100000417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.243.40"; classtype:trojan-activity; sid:100000418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.247.150"; classtype:trojan-activity; sid:100000419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.200.76.54"; classtype:trojan-activity; sid:100000420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.66.15"; classtype:trojan-activity; sid:100000421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.69.113"; classtype:trojan-activity; sid:100000422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.10.108"; classtype:trojan-activity; sid:100000423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.15.72"; classtype:trojan-activity; sid:100000424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.248.63.12"; classtype:trojan-activity; sid:100000425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.113.146"; classtype:trojan-activity; sid:100000426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.195.140"; classtype:trojan-activity; sid:100000427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.53.15"; classtype:trojan-activity; sid:100000428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.86.105.110"; classtype:trojan-activity; sid:100000429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.104.35"; classtype:trojan-activity; sid:100000430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.157.64"; classtype:trojan-activity; sid:100000431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.7.132"; classtype:trojan-activity; sid:100000432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.32.74"; classtype:trojan-activity; sid:100000433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.5.149"; classtype:trojan-activity; sid:100000434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.72.141"; classtype:trojan-activity; sid:100000435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.12.130"; classtype:trojan-activity; sid:100000436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.128.147"; classtype:trojan-activity; sid:100000437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.208.215"; classtype:trojan-activity; sid:100000438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.209.108"; classtype:trojan-activity; sid:100000439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.214.72"; classtype:trojan-activity; sid:100000440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.88.146"; classtype:trojan-activity; sid:100000441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.150"; classtype:trojan-activity; sid:100000442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.6"; classtype:trojan-activity; sid:100000443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.221.162"; classtype:trojan-activity; sid:100000444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.63.194"; classtype:trojan-activity; sid:100000445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.65.93"; classtype:trojan-activity; sid:100000446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.42.125.246"; classtype:trojan-activity; sid:100000447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.43.180.33"; classtype:trojan-activity; sid:100000448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.125.92"; classtype:trojan-activity; sid:100000449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.50.203"; classtype:trojan-activity; sid:100000450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.58.82"; classtype:trojan-activity; sid:100000451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.83.79.43"; classtype:trojan-activity; sid:100000452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.91.24.27"; classtype:trojan-activity; sid:100000453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.91.41.135"; classtype:trojan-activity; sid:100000454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.179.164"; classtype:trojan-activity; sid:100000455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.183.235"; classtype:trojan-activity; sid:100000456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.239.217"; classtype:trojan-activity; sid:100000457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.108.161.25"; classtype:trojan-activity; sid:100000458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.112.185.232"; classtype:trojan-activity; sid:100000459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.119.63.145"; classtype:trojan-activity; sid:100000460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.14.143.145"; classtype:trojan-activity; sid:100000461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.147.213.57"; classtype:trojan-activity; sid:100000462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.163.93.191"; classtype:trojan-activity; sid:100000463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.18.235"; classtype:trojan-activity; sid:100000464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.107.93"; classtype:trojan-activity; sid:100000465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.163.220"; classtype:trojan-activity; sid:100000466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.174.63"; classtype:trojan-activity; sid:100000467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.197.106"; classtype:trojan-activity; sid:100000468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.241.222"; classtype:trojan-activity; sid:100000469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.27.77"; classtype:trojan-activity; sid:100000470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.68.145"; classtype:trojan-activity; sid:100000471; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.170.241"; classtype:trojan-activity; sid:100000472; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.97.6"; classtype:trojan-activity; sid:100000473; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.26.33"; classtype:trojan-activity; sid:100000474; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.177.147.38"; classtype:trojan-activity; sid:100000475; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.248.123"; classtype:trojan-activity; sid:100000476; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.170.212"; classtype:trojan-activity; sid:100000477; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.43.1"; classtype:trojan-activity; sid:100000478; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.75.8"; classtype:trojan-activity; sid:100000479; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.18.38.144"; classtype:trojan-activity; sid:100000480; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.106.217"; classtype:trojan-activity; sid:100000481; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.108.227"; classtype:trojan-activity; sid:100000482; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.108.79"; classtype:trojan-activity; sid:100000483; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.33.161"; classtype:trojan-activity; sid:100000484; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.119.21"; classtype:trojan-activity; sid:100000485; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.124.203"; classtype:trojan-activity; sid:100000486; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.182.97.232"; classtype:trojan-activity; sid:100000487; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.183.115.103"; classtype:trojan-activity; sid:100000488; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.14.112"; classtype:trojan-activity; sid:100000489; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.172.199"; classtype:trojan-activity; sid:100000490; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.195.161"; classtype:trojan-activity; sid:100000491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.245.61"; classtype:trojan-activity; sid:100000492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.137.195"; classtype:trojan-activity; sid:100000493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.227.244"; classtype:trojan-activity; sid:100000494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.150.85"; classtype:trojan-activity; sid:100000495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.187.206"; classtype:trojan-activity; sid:100000496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.215.221"; classtype:trojan-activity; sid:100000497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.240.20"; classtype:trojan-activity; sid:100000498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.204.30.144"; classtype:trojan-activity; sid:100000499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.250.129.231"; classtype:trojan-activity; sid:100000500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.105.221"; classtype:trojan-activity; sid:100000501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.14.251"; classtype:trojan-activity; sid:100000502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.131.155"; classtype:trojan-activity; sid:100000503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.140.73"; classtype:trojan-activity; sid:100000504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.46"; classtype:trojan-activity; sid:100000505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.71"; classtype:trojan-activity; sid:100000506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.144.75"; classtype:trojan-activity; sid:100000507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.148.115"; classtype:trojan-activity; sid:100000508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.155.57"; classtype:trojan-activity; sid:100000509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.175.41"; classtype:trojan-activity; sid:100000510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.195.90"; classtype:trojan-activity; sid:100000511; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.206.43"; classtype:trojan-activity; sid:100000512; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.232.62"; classtype:trojan-activity; sid:100000513; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.132.113.2"; classtype:trojan-activity; sid:100000514; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.15.69.83"; classtype:trojan-activity; sid:100000515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.6"; classtype:trojan-activity; sid:100000516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.7"; classtype:trojan-activity; sid:100000517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.8"; classtype:trojan-activity; sid:100000518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.9"; classtype:trojan-activity; sid:100000519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.207.39.227"; classtype:trojan-activity; sid:100000520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.25.204.189"; classtype:trojan-activity; sid:100000521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.0.255.173"; classtype:trojan-activity; sid:100000522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.12.153.54"; classtype:trojan-activity; sid:100000523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.142.222.22"; classtype:trojan-activity; sid:100000524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.150.213.110"; classtype:trojan-activity; sid:100000525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.151.248.134"; classtype:trojan-activity; sid:100000526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.180"; classtype:trojan-activity; sid:100000527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.183"; classtype:trojan-activity; sid:100000528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.185"; classtype:trojan-activity; sid:100000529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.186"; classtype:trojan-activity; sid:100000530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.188"; classtype:trojan-activity; sid:100000531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.193"; classtype:trojan-activity; sid:100000532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.201"; classtype:trojan-activity; sid:100000533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.204"; classtype:trojan-activity; sid:100000534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.208"; classtype:trojan-activity; sid:100000535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.209"; classtype:trojan-activity; sid:100000536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.212"; classtype:trojan-activity; sid:100000537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.215"; classtype:trojan-activity; sid:100000538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.233"; classtype:trojan-activity; sid:100000539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.206"; classtype:trojan-activity; sid:100000540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.240"; classtype:trojan-activity; sid:100000541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.127.187"; classtype:trojan-activity; sid:100000542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.99.127"; classtype:trojan-activity; sid:100000543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.210.89.79"; classtype:trojan-activity; sid:100000544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.43.33.202"; classtype:trojan-activity; sid:100000545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.66.60"; classtype:trojan-activity; sid:100000546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.93.115"; classtype:trojan-activity; sid:100000547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.8.11"; classtype:trojan-activity; sid:100000548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.7.75.99"; classtype:trojan-activity; sid:100000549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.173.168"; classtype:trojan-activity; sid:100000550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.114.164"; classtype:trojan-activity; sid:100000551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.96.8"; classtype:trojan-activity; sid:100000552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.121.44.222"; classtype:trojan-activity; sid:100000553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.122.71.122"; classtype:trojan-activity; sid:100000554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.123.53.25"; classtype:trojan-activity; sid:100000555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.127.155.220"; classtype:trojan-activity; sid:100000556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.141.11.56"; classtype:trojan-activity; sid:100000557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.15.142.137"; classtype:trojan-activity; sid:100000558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.159.22.144"; classtype:trojan-activity; sid:100000559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.170.234.142"; classtype:trojan-activity; sid:100000560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.185.31.2"; classtype:trojan-activity; sid:100000561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.190.36.8"; classtype:trojan-activity; sid:100000562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.20.104.26"; classtype:trojan-activity; sid:100000563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.225.11.163"; classtype:trojan-activity; sid:100000564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.23.57.130"; classtype:trojan-activity; sid:100000565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.230.171.198"; classtype:trojan-activity; sid:100000566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.231.103.95"; classtype:trojan-activity; sid:100000567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.237.226.202"; classtype:trojan-activity; sid:100000568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.239.15.74"; classtype:trojan-activity; sid:100000569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.24.116.173"; classtype:trojan-activity; sid:100000570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.254.43.215"; classtype:trojan-activity; sid:100000571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.254.76.17"; classtype:trojan-activity; sid:100000572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.98.151"; classtype:trojan-activity; sid:100000573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.88.99.236"; classtype:trojan-activity; sid:100000574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.100.150.204"; classtype:trojan-activity; sid:100000575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.159.178.39"; classtype:trojan-activity; sid:100000576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.160.147.53"; classtype:trojan-activity; sid:100000577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.176.44.34"; classtype:trojan-activity; sid:100000578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.188.86.225"; classtype:trojan-activity; sid:100000579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.66.28"; classtype:trojan-activity; sid:100000580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.72.23"; classtype:trojan-activity; sid:100000581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.79.27"; classtype:trojan-activity; sid:100000582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.37.85"; classtype:trojan-activity; sid:100000583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.41.23"; classtype:trojan-activity; sid:100000584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.29.37"; classtype:trojan-activity; sid:100000585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.33.214"; classtype:trojan-activity; sid:100000586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.0.240.58"; classtype:trojan-activity; sid:100000587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.54.57"; classtype:trojan-activity; sid:100000588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.238"; classtype:trojan-activity; sid:100000589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.244"; classtype:trojan-activity; sid:100000590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.170.237"; classtype:trojan-activity; sid:100000591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.182.187"; classtype:trojan-activity; sid:100000592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.19.248"; classtype:trojan-activity; sid:100000593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.200.98"; classtype:trojan-activity; sid:100000594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.238.188"; classtype:trojan-activity; sid:100000595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.128.133.91"; classtype:trojan-activity; sid:100000596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.129.84.36"; classtype:trojan-activity; sid:100000597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.208.52"; classtype:trojan-activity; sid:100000598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.27.19"; classtype:trojan-activity; sid:100000599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.37.182"; classtype:trojan-activity; sid:100000600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.131.186.250"; classtype:trojan-activity; sid:100000601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.132.219.147"; classtype:trojan-activity; sid:100000602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.125.77"; classtype:trojan-activity; sid:100000603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.98.135"; classtype:trojan-activity; sid:100000604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.134.14.130"; classtype:trojan-activity; sid:100000605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.134.50.186"; classtype:trojan-activity; sid:100000606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.199.130"; classtype:trojan-activity; sid:100000607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.248.210"; classtype:trojan-activity; sid:100000608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.153.80.178"; classtype:trojan-activity; sid:100000609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.116.116"; classtype:trojan-activity; sid:100000610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.236.114"; classtype:trojan-activity; sid:100000611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.94.1"; classtype:trojan-activity; sid:100000612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.156.136.21"; classtype:trojan-activity; sid:100000613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.68.119"; classtype:trojan-activity; sid:100000614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.8.100"; classtype:trojan-activity; sid:100000615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.183.121.60"; classtype:trojan-activity; sid:100000616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.191.164.92"; classtype:trojan-activity; sid:100000617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.191.62.239"; classtype:trojan-activity; sid:100000618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.101.163"; classtype:trojan-activity; sid:100000619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.194.233"; classtype:trojan-activity; sid:100000620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.149.235"; classtype:trojan-activity; sid:100000621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.53.237"; classtype:trojan-activity; sid:100000622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.235.37"; classtype:trojan-activity; sid:100000623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.35.146"; classtype:trojan-activity; sid:100000624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.52.79"; classtype:trojan-activity; sid:100000625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.60.238"; classtype:trojan-activity; sid:100000626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.112.240"; classtype:trojan-activity; sid:100000627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.184.191"; classtype:trojan-activity; sid:100000628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.98.141"; classtype:trojan-activity; sid:100000629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.212.29.154"; classtype:trojan-activity; sid:100000630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.213.225.130"; classtype:trojan-activity; sid:100000631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.130.162"; classtype:trojan-activity; sid:100000632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.152.249"; classtype:trojan-activity; sid:100000633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.116.110"; classtype:trojan-activity; sid:100000634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.184.57"; classtype:trojan-activity; sid:100000635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.235.226.3"; classtype:trojan-activity; sid:100000636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.103.89"; classtype:trojan-activity; sid:100000637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.181.57"; classtype:trojan-activity; sid:100000638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.79.61"; classtype:trojan-activity; sid:100000639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.148.58"; classtype:trojan-activity; sid:100000640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.184.124"; classtype:trojan-activity; sid:100000641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.28.217.23"; classtype:trojan-activity; sid:100000642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.5.242"; classtype:trojan-activity; sid:100000643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.119.108.87"; classtype:trojan-activity; sid:100000644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.221.150"; classtype:trojan-activity; sid:100000645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.76.230"; classtype:trojan-activity; sid:100000646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.130.40.31"; classtype:trojan-activity; sid:100000647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.104.82"; classtype:trojan-activity; sid:100000648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.151.135"; classtype:trojan-activity; sid:100000649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.203.190"; classtype:trojan-activity; sid:100000650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.24.185"; classtype:trojan-activity; sid:100000651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.26.243"; classtype:trojan-activity; sid:100000652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.54.33"; classtype:trojan-activity; sid:100000653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.132.110.150"; classtype:trojan-activity; sid:100000654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.135.34.49"; classtype:trojan-activity; sid:100000655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.136.175"; classtype:trojan-activity; sid:100000656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.236.6"; classtype:trojan-activity; sid:100000657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.160.126.238"; classtype:trojan-activity; sid:100000658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.65.64"; classtype:trojan-activity; sid:100000659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.72.102"; classtype:trojan-activity; sid:100000660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.165.123.7"; classtype:trojan-activity; sid:100000661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.187.111.160"; classtype:trojan-activity; sid:100000662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.199.56.198"; classtype:trojan-activity; sid:100000663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.230.174.233"; classtype:trojan-activity; sid:100000664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.254.251.54"; classtype:trojan-activity; sid:100000665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.5.92.20"; classtype:trojan-activity; sid:100000666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.6.0.4"; classtype:trojan-activity; sid:100000667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.67.89.28"; classtype:trojan-activity; sid:100000668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.7.254.85"; classtype:trojan-activity; sid:100000669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.80.46.73"; classtype:trojan-activity; sid:100000670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.91.135.234"; classtype:trojan-activity; sid:100000671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.91.237.147"; classtype:trojan-activity; sid:100000672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.93.94.207"; classtype:trojan-activity; sid:100000673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.128.28.161"; classtype:trojan-activity; sid:100000674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.142.93.34"; classtype:trojan-activity; sid:100000675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.191.113.212"; classtype:trojan-activity; sid:100000676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.1.235"; classtype:trojan-activity; sid:100000677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.73.6"; classtype:trojan-activity; sid:100000678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.75.22"; classtype:trojan-activity; sid:100000679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.215.9"; classtype:trojan-activity; sid:100000680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.53.9"; classtype:trojan-activity; sid:100000681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.79.200.104"; classtype:trojan-activity; sid:100000682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"128.116.133.92"; classtype:trojan-activity; sid:100000683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"130.255.159.133"; classtype:trojan-activity; sid:100000684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"134.195.139.4"; classtype:trojan-activity; sid:100000685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"135.148.36.127"; classtype:trojan-activity; sid:100000686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"138.99.204.224"; classtype:trojan-activity; sid:100000687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.159.226.180"; classtype:trojan-activity; sid:100000688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.170.173.198"; classtype:trojan-activity; sid:100000689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.216.102.151"; classtype:trojan-activity; sid:100000690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.227.46.137"; classtype:trojan-activity; sid:100000691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.102.17.222"; classtype:trojan-activity; sid:100000692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.102.97.204"; classtype:trojan-activity; sid:100000693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.136.80.242"; classtype:trojan-activity; sid:100000694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.51"; classtype:trojan-activity; sid:100000695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.160.34.50"; classtype:trojan-activity; sid:100000696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.189.247.118"; classtype:trojan-activity; sid:100000697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.241.227.216"; classtype:trojan-activity; sid:100000698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.37.222.190"; classtype:trojan-activity; sid:100000699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.45.127.110"; classtype:trojan-activity; sid:100000700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.25.17"; classtype:trojan-activity; sid:100000701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.98.241"; classtype:trojan-activity; sid:100000702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.55.29.2"; classtype:trojan-activity; sid:100000703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"141.105.65.94"; classtype:trojan-activity; sid:100000704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.11.216.5"; classtype:trojan-activity; sid:100000705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.177.56.127"; classtype:trojan-activity; sid:100000706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"146.71.79.230"; classtype:trojan-activity; sid:100000707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"148.69.108.177"; classtype:trojan-activity; sid:100000708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.20.176.179"; classtype:trojan-activity; sid:100000709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.134"; classtype:trojan-activity; sid:100000710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.172"; classtype:trojan-activity; sid:100000711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.184"; classtype:trojan-activity; sid:100000712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.38"; classtype:trojan-activity; sid:100000713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.99"; classtype:trojan-activity; sid:100000714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.3.124.223"; classtype:trojan-activity; sid:100000715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.3.85.55"; classtype:trojan-activity; sid:100000716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14karatvisions.com"; classtype:trojan-activity; sid:100000717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"150.116.207.99"; classtype:trojan-activity; sid:100000718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.177.163.87"; classtype:trojan-activity; sid:100000719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.33.230.191"; classtype:trojan-activity; sid:100000720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.234.167"; classtype:trojan-activity; sid:100000721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.47.145"; classtype:trojan-activity; sid:100000722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.152.106"; classtype:trojan-activity; sid:100000723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.135.92"; classtype:trojan-activity; sid:100000724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"155.138.134.44"; classtype:trojan-activity; sid:100000725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.101.165.14"; classtype:trojan-activity; sid:100000726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.174.213.128"; classtype:trojan-activity; sid:100000727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.51.125.115"; classtype:trojan-activity; sid:100000728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"159.224.74.112"; classtype:trojan-activity; sid:100000729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.194.28.60"; classtype:trojan-activity; sid:100000730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.209.98.174"; classtype:trojan-activity; sid:100000731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.53.206.228"; classtype:trojan-activity; sid:100000732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"165.90.16.5"; classtype:trojan-activity; sid:100000733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"170.81.238.178"; classtype:trojan-activity; sid:100000734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.113.36.216"; classtype:trojan-activity; sid:100000735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.113.38.107"; classtype:trojan-activity; sid:100000736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.121.255.10"; classtype:trojan-activity; sid:100000737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.114.181"; classtype:trojan-activity; sid:100000738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.176.217"; classtype:trojan-activity; sid:100000739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.179.178"; classtype:trojan-activity; sid:100000740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.162.156"; classtype:trojan-activity; sid:100000741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.174.198"; classtype:trojan-activity; sid:100000742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.105.36.168"; classtype:trojan-activity; sid:100000743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.114.244.127"; classtype:trojan-activity; sid:100000744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.185"; classtype:trojan-activity; sid:100000745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.190"; classtype:trojan-activity; sid:100000746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.79.106"; classtype:trojan-activity; sid:100000747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.81.19"; classtype:trojan-activity; sid:100000748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.93.194.114"; classtype:trojan-activity; sid:100000749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.167.85.89"; classtype:trojan-activity; sid:100000750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.169.46.85"; classtype:trojan-activity; sid:100000751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.19.58.108"; classtype:trojan-activity; sid:100000752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.233.85.171"; classtype:trojan-activity; sid:100000753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.235.209.70"; classtype:trojan-activity; sid:100000754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.25.113.8"; classtype:trojan-activity; sid:100000755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.95.134"; classtype:trojan-activity; sid:100000756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.97.25"; classtype:trojan-activity; sid:100000757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.119.108"; classtype:trojan-activity; sid:100000758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.92.166"; classtype:trojan-activity; sid:100000759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.106.33.85"; classtype:trojan-activity; sid:100000760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.48.181.23"; classtype:trojan-activity; sid:100000761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.61.3.149"; classtype:trojan-activity; sid:100000762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.73.246.193"; classtype:trojan-activity; sid:100000763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.81.78.7"; classtype:trojan-activity; sid:100000764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.83.73.163"; classtype:trojan-activity; sid:100000765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.10.147.167"; classtype:trojan-activity; sid:100000766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.11.193.66"; classtype:trojan-activity; sid:100000767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.11.65.112"; classtype:trojan-activity; sid:100000768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.117.66.74"; classtype:trojan-activity; sid:100000769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.145.200.216"; classtype:trojan-activity; sid:100000770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.169.13.182"; classtype:trojan-activity; sid:100000771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.201.104.192"; classtype:trojan-activity; sid:100000772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.208.230.8"; classtype:trojan-activity; sid:100000773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.42.46.118"; classtype:trojan-activity; sid:100000774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.9.24.110"; classtype:trojan-activity; sid:100000775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.9.90.89"; classtype:trojan-activity; sid:100000776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.14"; classtype:trojan-activity; sid:100000777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.249"; classtype:trojan-activity; sid:100000778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.35"; classtype:trojan-activity; sid:100000779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.63"; classtype:trojan-activity; sid:100000780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.66"; classtype:trojan-activity; sid:100000781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.67"; classtype:trojan-activity; sid:100000782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.104"; classtype:trojan-activity; sid:100000783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.113"; classtype:trojan-activity; sid:100000784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.60"; classtype:trojan-activity; sid:100000785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.65"; classtype:trojan-activity; sid:100000786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.66"; classtype:trojan-activity; sid:100000787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.68"; classtype:trojan-activity; sid:100000788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.84"; classtype:trojan-activity; sid:100000789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.91"; classtype:trojan-activity; sid:100000790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.93"; classtype:trojan-activity; sid:100000791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.12.117.70"; classtype:trojan-activity; sid:100000792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.4.115"; classtype:trojan-activity; sid:100000793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.115"; classtype:trojan-activity; sid:100000794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.127"; classtype:trojan-activity; sid:100000795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.9.243"; classtype:trojan-activity; sid:100000796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.124.7.225"; classtype:trojan-activity; sid:100000797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.221.188.251"; classtype:trojan-activity; sid:100000798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.240.84.106"; classtype:trojan-activity; sid:100000799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.11.92.78"; classtype:trojan-activity; sid:100000800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.131.226.235"; classtype:trojan-activity; sid:100000801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.229.64.218"; classtype:trojan-activity; sid:100000802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.54.82.154"; classtype:trojan-activity; sid:100000803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.86.99.5"; classtype:trojan-activity; sid:100000804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.124.182.187"; classtype:trojan-activity; sid:100000805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.142.15"; classtype:trojan-activity; sid:100000806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.150.174.65"; classtype:trojan-activity; sid:100000807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.151.143.2"; classtype:trojan-activity; sid:100000808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.165.122.141"; classtype:trojan-activity; sid:100000809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.0.200"; classtype:trojan-activity; sid:100000810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.137"; classtype:trojan-activity; sid:100000811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.179"; classtype:trojan-activity; sid:100000812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.248"; classtype:trojan-activity; sid:100000813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.249"; classtype:trojan-activity; sid:100000814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.250"; classtype:trojan-activity; sid:100000815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.44"; classtype:trojan-activity; sid:100000816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.80"; classtype:trojan-activity; sid:100000817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.151"; classtype:trojan-activity; sid:100000818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.7"; classtype:trojan-activity; sid:100000819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.110"; classtype:trojan-activity; sid:100000820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.232"; classtype:trojan-activity; sid:100000821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.171"; classtype:trojan-activity; sid:100000822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.67"; classtype:trojan-activity; sid:100000823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.98"; classtype:trojan-activity; sid:100000824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.155"; classtype:trojan-activity; sid:100000825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.69"; classtype:trojan-activity; sid:100000826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.95"; classtype:trojan-activity; sid:100000827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.193"; classtype:trojan-activity; sid:100000828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.0"; classtype:trojan-activity; sid:100000829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.245"; classtype:trojan-activity; sid:100000830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.83"; classtype:trojan-activity; sid:100000831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.105"; classtype:trojan-activity; sid:100000832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.87"; classtype:trojan-activity; sid:100000833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.129"; classtype:trojan-activity; sid:100000834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.26"; classtype:trojan-activity; sid:100000835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.126"; classtype:trojan-activity; sid:100000836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.239"; classtype:trojan-activity; sid:100000837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.252"; classtype:trojan-activity; sid:100000838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.190"; classtype:trojan-activity; sid:100000839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.195"; classtype:trojan-activity; sid:100000840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.206"; classtype:trojan-activity; sid:100000841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.135"; classtype:trojan-activity; sid:100000842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.139"; classtype:trojan-activity; sid:100000843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.140"; classtype:trojan-activity; sid:100000844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.147"; classtype:trojan-activity; sid:100000845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.159"; classtype:trojan-activity; sid:100000846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.46"; classtype:trojan-activity; sid:100000847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.58"; classtype:trojan-activity; sid:100000848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.114"; classtype:trojan-activity; sid:100000849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.110"; classtype:trojan-activity; sid:100000850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.209"; classtype:trojan-activity; sid:100000851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.101"; classtype:trojan-activity; sid:100000852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.138"; classtype:trojan-activity; sid:100000853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.30"; classtype:trojan-activity; sid:100000854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.112"; classtype:trojan-activity; sid:100000855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.146"; classtype:trojan-activity; sid:100000856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.102"; classtype:trojan-activity; sid:100000857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.114"; classtype:trojan-activity; sid:100000858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.69"; classtype:trojan-activity; sid:100000859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.70"; classtype:trojan-activity; sid:100000860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.93"; classtype:trojan-activity; sid:100000861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.123"; classtype:trojan-activity; sid:100000862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.151"; classtype:trojan-activity; sid:100000863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.199"; classtype:trojan-activity; sid:100000864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.228"; classtype:trojan-activity; sid:100000865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.28"; classtype:trojan-activity; sid:100000866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.74"; classtype:trojan-activity; sid:100000867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.9"; classtype:trojan-activity; sid:100000868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.1"; classtype:trojan-activity; sid:100000869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.168"; classtype:trojan-activity; sid:100000870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.191"; classtype:trojan-activity; sid:100000871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.2"; classtype:trojan-activity; sid:100000872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.202"; classtype:trojan-activity; sid:100000873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.248"; classtype:trojan-activity; sid:100000874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.26"; classtype:trojan-activity; sid:100000875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.30"; classtype:trojan-activity; sid:100000876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.91"; classtype:trojan-activity; sid:100000877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.131"; classtype:trojan-activity; sid:100000878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.155"; classtype:trojan-activity; sid:100000879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.4"; classtype:trojan-activity; sid:100000880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.14"; classtype:trojan-activity; sid:100000881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.160"; classtype:trojan-activity; sid:100000882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.220"; classtype:trojan-activity; sid:100000883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.88"; classtype:trojan-activity; sid:100000884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.129"; classtype:trojan-activity; sid:100000885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.252"; classtype:trojan-activity; sid:100000886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.46"; classtype:trojan-activity; sid:100000887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.202"; classtype:trojan-activity; sid:100000888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.231"; classtype:trojan-activity; sid:100000889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.43"; classtype:trojan-activity; sid:100000890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.222"; classtype:trojan-activity; sid:100000891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.254"; classtype:trojan-activity; sid:100000892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.199"; classtype:trojan-activity; sid:100000893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.215"; classtype:trojan-activity; sid:100000894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.108"; classtype:trojan-activity; sid:100000895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.116"; classtype:trojan-activity; sid:100000896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.251"; classtype:trojan-activity; sid:100000897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.7"; classtype:trojan-activity; sid:100000898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.73"; classtype:trojan-activity; sid:100000899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.118"; classtype:trojan-activity; sid:100000900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.61"; classtype:trojan-activity; sid:100000901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.23"; classtype:trojan-activity; sid:100000902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.37"; classtype:trojan-activity; sid:100000903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.75"; classtype:trojan-activity; sid:100000904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.163"; classtype:trojan-activity; sid:100000905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.174"; classtype:trojan-activity; sid:100000906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.91"; classtype:trojan-activity; sid:100000907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.209"; classtype:trojan-activity; sid:100000908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.5"; classtype:trojan-activity; sid:100000909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.117"; classtype:trojan-activity; sid:100000910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.70"; classtype:trojan-activity; sid:100000911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.97"; classtype:trojan-activity; sid:100000912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.149"; classtype:trojan-activity; sid:100000913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.237"; classtype:trojan-activity; sid:100000914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.144"; classtype:trojan-activity; sid:100000915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.176"; classtype:trojan-activity; sid:100000916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.146"; classtype:trojan-activity; sid:100000917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.172"; classtype:trojan-activity; sid:100000918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.117"; classtype:trojan-activity; sid:100000919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.152"; classtype:trojan-activity; sid:100000920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.177"; classtype:trojan-activity; sid:100000921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.56"; classtype:trojan-activity; sid:100000922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.215"; classtype:trojan-activity; sid:100000923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.114"; classtype:trojan-activity; sid:100000924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.171"; classtype:trojan-activity; sid:100000925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.213"; classtype:trojan-activity; sid:100000926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.32"; classtype:trojan-activity; sid:100000927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.37"; classtype:trojan-activity; sid:100000928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.46"; classtype:trojan-activity; sid:100000929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.239"; classtype:trojan-activity; sid:100000930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.47"; classtype:trojan-activity; sid:100000931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.21"; classtype:trojan-activity; sid:100000932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.172"; classtype:trojan-activity; sid:100000933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.214"; classtype:trojan-activity; sid:100000934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.133"; classtype:trojan-activity; sid:100000935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.151"; classtype:trojan-activity; sid:100000936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.213"; classtype:trojan-activity; sid:100000937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.73"; classtype:trojan-activity; sid:100000938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.146"; classtype:trojan-activity; sid:100000939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.220"; classtype:trojan-activity; sid:100000940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.89"; classtype:trojan-activity; sid:100000941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.162"; classtype:trojan-activity; sid:100000942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.7"; classtype:trojan-activity; sid:100000943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.217"; classtype:trojan-activity; sid:100000944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.247"; classtype:trojan-activity; sid:100000945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.253"; classtype:trojan-activity; sid:100000946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.36"; classtype:trojan-activity; sid:100000947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.83"; classtype:trojan-activity; sid:100000948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.126"; classtype:trojan-activity; sid:100000949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.218"; classtype:trojan-activity; sid:100000950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.57"; classtype:trojan-activity; sid:100000951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.6"; classtype:trojan-activity; sid:100000952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.103"; classtype:trojan-activity; sid:100000953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.132"; classtype:trojan-activity; sid:100000954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.200"; classtype:trojan-activity; sid:100000955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.144"; classtype:trojan-activity; sid:100000956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.72"; classtype:trojan-activity; sid:100000957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.136"; classtype:trojan-activity; sid:100000958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.228"; classtype:trojan-activity; sid:100000959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.101"; classtype:trojan-activity; sid:100000960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.6"; classtype:trojan-activity; sid:100000961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.121"; classtype:trojan-activity; sid:100000962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.223"; classtype:trojan-activity; sid:100000963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.229"; classtype:trojan-activity; sid:100000964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.238"; classtype:trojan-activity; sid:100000965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.244"; classtype:trojan-activity; sid:100000966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.0"; classtype:trojan-activity; sid:100000967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.217"; classtype:trojan-activity; sid:100000968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.70"; classtype:trojan-activity; sid:100000969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.90"; classtype:trojan-activity; sid:100000970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.201"; classtype:trojan-activity; sid:100000971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.205"; classtype:trojan-activity; sid:100000972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.214"; classtype:trojan-activity; sid:100000973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.26"; classtype:trojan-activity; sid:100000974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.129"; classtype:trojan-activity; sid:100000975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.137"; classtype:trojan-activity; sid:100000976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.41"; classtype:trojan-activity; sid:100000977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.42"; classtype:trojan-activity; sid:100000978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.8"; classtype:trojan-activity; sid:100000979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.143"; classtype:trojan-activity; sid:100000980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.51"; classtype:trojan-activity; sid:100000981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.57"; classtype:trojan-activity; sid:100000982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.10"; classtype:trojan-activity; sid:100000983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.177"; classtype:trojan-activity; sid:100000984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.236"; classtype:trojan-activity; sid:100000985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.56"; classtype:trojan-activity; sid:100000986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.180"; classtype:trojan-activity; sid:100000987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.212"; classtype:trojan-activity; sid:100000988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.216"; classtype:trojan-activity; sid:100000989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.151"; classtype:trojan-activity; sid:100000990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.254"; classtype:trojan-activity; sid:100000991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.5"; classtype:trojan-activity; sid:100000992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.58"; classtype:trojan-activity; sid:100000993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.14"; classtype:trojan-activity; sid:100000994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.211"; classtype:trojan-activity; sid:100000995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.11"; classtype:trojan-activity; sid:100000996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.82"; classtype:trojan-activity; sid:100000997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.87"; classtype:trojan-activity; sid:100000998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.134"; classtype:trojan-activity; sid:100000999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.183"; classtype:trojan-activity; sid:100001000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.79"; classtype:trojan-activity; sid:100001001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.33"; classtype:trojan-activity; sid:100001002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.115"; classtype:trojan-activity; sid:100001003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.140"; classtype:trojan-activity; sid:100001004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.141"; classtype:trojan-activity; sid:100001005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.157"; classtype:trojan-activity; sid:100001006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.182"; classtype:trojan-activity; sid:100001007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.195"; classtype:trojan-activity; sid:100001008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.134"; classtype:trojan-activity; sid:100001009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.209"; classtype:trojan-activity; sid:100001010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.212"; classtype:trojan-activity; sid:100001011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.221"; classtype:trojan-activity; sid:100001012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.70"; classtype:trojan-activity; sid:100001013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.81"; classtype:trojan-activity; sid:100001014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.21"; classtype:trojan-activity; sid:100001015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.156"; classtype:trojan-activity; sid:100001016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.186"; classtype:trojan-activity; sid:100001017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.192"; classtype:trojan-activity; sid:100001018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.116"; classtype:trojan-activity; sid:100001019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.123"; classtype:trojan-activity; sid:100001020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.209"; classtype:trojan-activity; sid:100001021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.44"; classtype:trojan-activity; sid:100001022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.128"; classtype:trojan-activity; sid:100001023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.153"; classtype:trojan-activity; sid:100001024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.67"; classtype:trojan-activity; sid:100001025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.105"; classtype:trojan-activity; sid:100001026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.14"; classtype:trojan-activity; sid:100001027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.35"; classtype:trojan-activity; sid:100001028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.60"; classtype:trojan-activity; sid:100001029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.79"; classtype:trojan-activity; sid:100001030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.218"; classtype:trojan-activity; sid:100001031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.179"; classtype:trojan-activity; sid:100001032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.222"; classtype:trojan-activity; sid:100001033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.65"; classtype:trojan-activity; sid:100001034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.181"; classtype:trojan-activity; sid:100001035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.244"; classtype:trojan-activity; sid:100001036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.47"; classtype:trojan-activity; sid:100001037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.169"; classtype:trojan-activity; sid:100001038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.2"; classtype:trojan-activity; sid:100001039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.242"; classtype:trojan-activity; sid:100001040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.89"; classtype:trojan-activity; sid:100001041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.226"; classtype:trojan-activity; sid:100001042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.31"; classtype:trojan-activity; sid:100001043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.2"; classtype:trojan-activity; sid:100001044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.247"; classtype:trojan-activity; sid:100001045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.215"; classtype:trojan-activity; sid:100001046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.23"; classtype:trojan-activity; sid:100001047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.53"; classtype:trojan-activity; sid:100001048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.59"; classtype:trojan-activity; sid:100001049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.146"; classtype:trojan-activity; sid:100001050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.42"; classtype:trojan-activity; sid:100001051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.91"; classtype:trojan-activity; sid:100001052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.4"; classtype:trojan-activity; sid:100001053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.121"; classtype:trojan-activity; sid:100001054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.217"; classtype:trojan-activity; sid:100001055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.6"; classtype:trojan-activity; sid:100001056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.179"; classtype:trojan-activity; sid:100001057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.198"; classtype:trojan-activity; sid:100001058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.4"; classtype:trojan-activity; sid:100001059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.4"; classtype:trojan-activity; sid:100001060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.1"; classtype:trojan-activity; sid:100001061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.102"; classtype:trojan-activity; sid:100001062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.92"; classtype:trojan-activity; sid:100001063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.143"; classtype:trojan-activity; sid:100001064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.27"; classtype:trojan-activity; sid:100001065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.32"; classtype:trojan-activity; sid:100001066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.40"; classtype:trojan-activity; sid:100001067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.61"; classtype:trojan-activity; sid:100001068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.120"; classtype:trojan-activity; sid:100001069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.251"; classtype:trojan-activity; sid:100001070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.113"; classtype:trojan-activity; sid:100001071; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.83"; classtype:trojan-activity; sid:100001072; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.120"; classtype:trojan-activity; sid:100001073; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.130"; classtype:trojan-activity; sid:100001074; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.77"; classtype:trojan-activity; sid:100001075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.19.183.14"; classtype:trojan-activity; sid:100001076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.205.101.33"; classtype:trojan-activity; sid:100001077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.21.164.68"; classtype:trojan-activity; sid:100001078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.217.8.194"; classtype:trojan-activity; sid:100001079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.22.117.102"; classtype:trojan-activity; sid:100001080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.222.252.130"; classtype:trojan-activity; sid:100001081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.34.183.30"; classtype:trojan-activity; sid:100001082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.48.235.59"; classtype:trojan-activity; sid:100001083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.95.136.35"; classtype:trojan-activity; sid:100001084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.159.58.134"; classtype:trojan-activity; sid:100001085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.60.84.7"; classtype:trojan-activity; sid:100001086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.99.210.161"; classtype:trojan-activity; sid:100001087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.114.60.229"; classtype:trojan-activity; sid:100001088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.116.203.220"; classtype:trojan-activity; sid:100001089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.122.13.227"; classtype:trojan-activity; sid:100001090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.123.208.250"; classtype:trojan-activity; sid:100001091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.157.66.204"; classtype:trojan-activity; sid:100001092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.175.236.209"; classtype:trojan-activity; sid:100001093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.105.41"; classtype:trojan-activity; sid:100001094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.110.243"; classtype:trojan-activity; sid:100001095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.165.230"; classtype:trojan-activity; sid:100001096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.214.171"; classtype:trojan-activity; sid:100001097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.34.51"; classtype:trojan-activity; sid:100001098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.96.248"; classtype:trojan-activity; sid:100001099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.104.65"; classtype:trojan-activity; sid:100001100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.180.6"; classtype:trojan-activity; sid:100001101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.242.73"; classtype:trojan-activity; sid:100001102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.218.5.171"; classtype:trojan-activity; sid:100001103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.248.80.38"; classtype:trojan-activity; sid:100001104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.111.36"; classtype:trojan-activity; sid:100001105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.53.93"; classtype:trojan-activity; sid:100001106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.94.170.166"; classtype:trojan-activity; sid:100001107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.138.154"; classtype:trojan-activity; sid:100001108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.218.238"; classtype:trojan-activity; sid:100001109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.218.6"; classtype:trojan-activity; sid:100001110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.143.60.163"; classtype:trojan-activity; sid:100001111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.193.107.10"; classtype:trojan-activity; sid:100001112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.222"; classtype:trojan-activity; sid:100001113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.230"; classtype:trojan-activity; sid:100001114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.210.45.42"; classtype:trojan-activity; sid:100001115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.215.47.82"; classtype:trojan-activity; sid:100001116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.224.242.131"; classtype:trojan-activity; sid:100001117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.236.4"; classtype:trojan-activity; sid:100001118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.59.162"; classtype:trojan-activity; sid:100001119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.113.209.187"; classtype:trojan-activity; sid:100001120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.108.244"; classtype:trojan-activity; sid:100001121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.43.47"; classtype:trojan-activity; sid:100001122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.60.73"; classtype:trojan-activity; sid:100001123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.61.252"; classtype:trojan-activity; sid:100001124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.99.150"; classtype:trojan-activity; sid:100001125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.43.185"; classtype:trojan-activity; sid:100001126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.120.8"; classtype:trojan-activity; sid:100001127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.164.128"; classtype:trojan-activity; sid:100001128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.202.130"; classtype:trojan-activity; sid:100001129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.22"; classtype:trojan-activity; sid:100001130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.46"; classtype:trojan-activity; sid:100001131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.26.37"; classtype:trojan-activity; sid:100001132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.152.3"; classtype:trojan-activity; sid:100001133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.160.98.250"; classtype:trojan-activity; sid:100001134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.233.0.252"; classtype:trojan-activity; sid:100001135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.235.252.31"; classtype:trojan-activity; sid:100001136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.53.197.62"; classtype:trojan-activity; sid:100001137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.105.225.154"; classtype:trojan-activity; sid:100001138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.109.169.45"; classtype:trojan-activity; sid:100001139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.128.152.115"; classtype:trojan-activity; sid:100001140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.29.191"; classtype:trojan-activity; sid:100001141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.92.207.147"; classtype:trojan-activity; sid:100001142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.164.185.41"; classtype:trojan-activity; sid:100001143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.175.115.10"; classtype:trojan-activity; sid:100001144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.74.149.230"; classtype:trojan-activity; sid:100001145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.106.209.68"; classtype:trojan-activity; sid:100001146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.107.3.8"; classtype:trojan-activity; sid:100001147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.117.2.107"; classtype:trojan-activity; sid:100001148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.172.110.235"; classtype:trojan-activity; sid:100001149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.174.101.41"; classtype:trojan-activity; sid:100001150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.181.10.234"; classtype:trojan-activity; sid:100001151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.112"; classtype:trojan-activity; sid:100001152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.54"; classtype:trojan-activity; sid:100001153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.77"; classtype:trojan-activity; sid:100001154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.93"; classtype:trojan-activity; sid:100001155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.221.3.244"; classtype:trojan-activity; sid:100001156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.222.58.152"; classtype:trojan-activity; sid:100001157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.228.141.74"; classtype:trojan-activity; sid:100001158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.233.186.151"; classtype:trojan-activity; sid:100001159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.26.113.95"; classtype:trojan-activity; sid:100001160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.34.16.231"; classtype:trojan-activity; sid:100001161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.43.19.151"; classtype:trojan-activity; sid:100001162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.55.1.182"; classtype:trojan-activity; sid:100001163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.68.230.207"; classtype:trojan-activity; sid:100001164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.81.157.186"; classtype:trojan-activity; sid:100001165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.185"; classtype:trojan-activity; sid:100001166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.160"; classtype:trojan-activity; sid:100001167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.161"; classtype:trojan-activity; sid:100001168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.219"; classtype:trojan-activity; sid:100001169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.80"; classtype:trojan-activity; sid:100001170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.151.144.85"; classtype:trojan-activity; sid:100001171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.219.164"; classtype:trojan-activity; sid:100001172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.112"; classtype:trojan-activity; sid:100001173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.77"; classtype:trojan-activity; sid:100001174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.91"; classtype:trojan-activity; sid:100001175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.253.150"; classtype:trojan-activity; sid:100001176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.225.120.173"; classtype:trojan-activity; sid:100001177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.232.44.86"; classtype:trojan-activity; sid:100001178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.28.60.184"; classtype:trojan-activity; sid:100001179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.34.4.40"; classtype:trojan-activity; sid:100001180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.73.188.132"; classtype:trojan-activity; sid:100001181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.12.10.98"; classtype:trojan-activity; sid:100001182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.188.124.229"; classtype:trojan-activity; sid:100001183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.212.200.162"; classtype:trojan-activity; sid:100001184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.21.14"; classtype:trojan-activity; sid:100001185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.231.246"; classtype:trojan-activity; sid:100001186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.113.81.17"; classtype:trojan-activity; sid:100001187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.13.179.87"; classtype:trojan-activity; sid:100001188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.138.200.32"; classtype:trojan-activity; sid:100001189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.143.220.152"; classtype:trojan-activity; sid:100001190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.152.41.141"; classtype:trojan-activity; sid:100001191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.178.50"; classtype:trojan-activity; sid:100001192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.179.127"; classtype:trojan-activity; sid:100001193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.199.59"; classtype:trojan-activity; sid:100001194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.242.242.144"; classtype:trojan-activity; sid:100001195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.81.100.83"; classtype:trojan-activity; sid:100001196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.83.202.25"; classtype:trojan-activity; sid:100001197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"189.222.157.241"; classtype:trojan-activity; sid:100001198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.0.42.106"; classtype:trojan-activity; sid:100001199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.109.178.139"; classtype:trojan-activity; sid:100001200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.110.161.252"; classtype:trojan-activity; sid:100001201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.111.151.164"; classtype:trojan-activity; sid:100001202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.119.207.58"; classtype:trojan-activity; sid:100001203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.12.99.194"; classtype:trojan-activity; sid:100001204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.160"; classtype:trojan-activity; sid:100001205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.3"; classtype:trojan-activity; sid:100001206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.37"; classtype:trojan-activity; sid:100001207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.41"; classtype:trojan-activity; sid:100001208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.42"; classtype:trojan-activity; sid:100001209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.15.212"; classtype:trojan-activity; sid:100001210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.20.14"; classtype:trojan-activity; sid:100001211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.147.16.184"; classtype:trojan-activity; sid:100001212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.159.240.9"; classtype:trojan-activity; sid:100001213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.187.55.150"; classtype:trojan-activity; sid:100001214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.210.214.130"; classtype:trojan-activity; sid:100001215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.177.39"; classtype:trojan-activity; sid:100001216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.226.63"; classtype:trojan-activity; sid:100001217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.49.207"; classtype:trojan-activity; sid:100001218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.214.24.194"; classtype:trojan-activity; sid:100001219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.216.140.123"; classtype:trojan-activity; sid:100001220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.65.206.162"; classtype:trojan-activity; sid:100001221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.73.12.149"; classtype:trojan-activity; sid:100001222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.92.4.231"; classtype:trojan-activity; sid:100001223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.135"; classtype:trojan-activity; sid:100001224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.200"; classtype:trojan-activity; sid:100001225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.41.33"; classtype:trojan-activity; sid:100001226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"191.254.225.48"; classtype:trojan-activity; sid:100001227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"191.255.248.220"; classtype:trojan-activity; sid:100001228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.153.57.63"; classtype:trojan-activity; sid:100001229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.210.175.130"; classtype:trojan-activity; sid:100001230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.185.106"; classtype:trojan-activity; sid:100001231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.209.27"; classtype:trojan-activity; sid:100001232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.220.55"; classtype:trojan-activity; sid:100001233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.228.67"; classtype:trojan-activity; sid:100001234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.230.74"; classtype:trojan-activity; sid:100001235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.3.152.166"; classtype:trojan-activity; sid:100001236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.3.73.205"; classtype:trojan-activity; sid:100001237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.99.240.77"; classtype:trojan-activity; sid:100001238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.142.146.25"; classtype:trojan-activity; sid:100001239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.228.135.144"; classtype:trojan-activity; sid:100001240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.113.107.243"; classtype:trojan-activity; sid:100001241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.147.142.230"; classtype:trojan-activity; sid:100001242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.15.36.167"; classtype:trojan-activity; sid:100001243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.15.36.238"; classtype:trojan-activity; sid:100001244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.152.35.139"; classtype:trojan-activity; sid:100001245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.38.20.199"; classtype:trojan-activity; sid:100001246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.139.126.51"; classtype:trojan-activity; sid:100001247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.162.70.104"; classtype:trojan-activity; sid:100001248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.228.231.218"; classtype:trojan-activity; sid:100001249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.24.94.187"; classtype:trojan-activity; sid:100001250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.202.26.182"; classtype:trojan-activity; sid:100001251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.218.48.82"; classtype:trojan-activity; sid:100001252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.166.203"; classtype:trojan-activity; sid:100001253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.50.27.115"; classtype:trojan-activity; sid:100001254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.133.218"; classtype:trojan-activity; sid:100001255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.174.104"; classtype:trojan-activity; sid:100001256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.207.121"; classtype:trojan-activity; sid:100001257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.213.57"; classtype:trojan-activity; sid:100001258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.251.105"; classtype:trojan-activity; sid:100001259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.251.121"; classtype:trojan-activity; sid:100001260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.46.132.132"; classtype:trojan-activity; sid:100001261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.46.201.76"; classtype:trojan-activity; sid:100001262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"199.188.101.109"; classtype:trojan-activity; sid:100001263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1am.co.nz"; classtype:trojan-activity; sid:100001264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.229.89.119"; classtype:trojan-activity; sid:100001265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.239.22.188"; classtype:trojan-activity; sid:100001266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.37.149.230"; classtype:trojan-activity; sid:100001267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.37.203.65"; classtype:trojan-activity; sid:100001268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.4.24"; classtype:trojan-activity; sid:100001269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.125.182"; classtype:trojan-activity; sid:100001270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.92.184"; classtype:trojan-activity; sid:100001271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.57.122.107"; classtype:trojan-activity; sid:100001272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.83.152.16"; classtype:trojan-activity; sid:100001273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"20.185.42.197"; classtype:trojan-activity; sid:100001274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.105.167.98"; classtype:trojan-activity; sid:100001275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.111.189.70"; classtype:trojan-activity; sid:100001276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.194.4.24"; classtype:trojan-activity; sid:100001277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.2.161.171"; classtype:trojan-activity; sid:100001278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.30.132.50"; classtype:trojan-activity; sid:100001279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.142.147.89"; classtype:trojan-activity; sid:100001280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.170.46.2"; classtype:trojan-activity; sid:100001281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.184.163.170"; classtype:trojan-activity; sid:100001282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.187.102.73"; classtype:trojan-activity; sid:100001283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.200.254.86"; classtype:trojan-activity; sid:100001284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.203.221.20"; classtype:trojan-activity; sid:100001285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.203.27.37"; classtype:trojan-activity; sid:100001286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.107.233.41"; classtype:trojan-activity; sid:100001287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.150.176.100"; classtype:trojan-activity; sid:100001288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.175.103.10"; classtype:trojan-activity; sid:100001289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.29.95.12"; classtype:trojan-activity; sid:100001290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.4.124.58"; classtype:trojan-activity; sid:100001291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.176.114"; classtype:trojan-activity; sid:100001292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.191.174"; classtype:trojan-activity; sid:100001293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.74.236.9"; classtype:trojan-activity; sid:100001294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.109.201.243"; classtype:trojan-activity; sid:100001295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.170.123.78"; classtype:trojan-activity; sid:100001296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.204.232.18"; classtype:trojan-activity; sid:100001297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.229.21.56"; classtype:trojan-activity; sid:100001298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.236.190.28"; classtype:trojan-activity; sid:100001299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.238.86.202"; classtype:trojan-activity; sid:100001300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.70.166.107"; classtype:trojan-activity; sid:100001301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.77.80.159"; classtype:trojan-activity; sid:100001302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.119.166"; classtype:trojan-activity; sid:100001303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.171.138"; classtype:trojan-activity; sid:100001304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.82.36.34"; classtype:trojan-activity; sid:100001305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.93.6.28"; classtype:trojan-activity; sid:100001306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"204.195.116.171"; classtype:trojan-activity; sid:100001307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"205.185.115.74"; classtype:trojan-activity; sid:100001308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"205.185.116.94"; classtype:trojan-activity; sid:100001309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"206.248.137.132"; classtype:trojan-activity; sid:100001310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"206.47.41.166"; classtype:trojan-activity; sid:100001311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.180.228.101"; classtype:trojan-activity; sid:100001312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.5.32.6"; classtype:trojan-activity; sid:100001313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"208.163.58.18"; classtype:trojan-activity; sid:100001314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"208.75.27.157"; classtype:trojan-activity; sid:100001315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.39.50"; classtype:trojan-activity; sid:100001316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.190"; classtype:trojan-activity; sid:100001317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.31"; classtype:trojan-activity; sid:100001318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.124.149.19"; classtype:trojan-activity; sid:100001319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.180.17.140"; classtype:trojan-activity; sid:100001320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.152.122"; classtype:trojan-activity; sid:100001321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.153.142"; classtype:trojan-activity; sid:100001322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.234.93"; classtype:trojan-activity; sid:100001323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.237.70"; classtype:trojan-activity; sid:100001324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.245.109"; classtype:trojan-activity; sid:100001325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.68.242.114"; classtype:trojan-activity; sid:100001326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.96.116.236"; classtype:trojan-activity; sid:100001327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.116.220.37"; classtype:trojan-activity; sid:100001328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.132.204"; classtype:trojan-activity; sid:100001329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.75.220"; classtype:trojan-activity; sid:100001330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.204.215.157"; classtype:trojan-activity; sid:100001331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.66.179"; classtype:trojan-activity; sid:100001332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.93.93"; classtype:trojan-activity; sid:100001333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.216.66.105"; classtype:trojan-activity; sid:100001334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.114.96"; classtype:trojan-activity; sid:100001335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.120.13"; classtype:trojan-activity; sid:100001336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.246.137"; classtype:trojan-activity; sid:100001337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.238.83.238"; classtype:trojan-activity; sid:100001338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.247.113.49"; classtype:trojan-activity; sid:100001339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.247.5.96"; classtype:trojan-activity; sid:100001340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.32.122.110"; classtype:trojan-activity; sid:100001341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.122.86.105"; classtype:trojan-activity; sid:100001342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.143.227.22"; classtype:trojan-activity; sid:100001343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.156.215.178"; classtype:trojan-activity; sid:100001344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.46.197.114"; classtype:trojan-activity; sid:100001345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.56.197.230"; classtype:trojan-activity; sid:100001346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.8.251.211"; classtype:trojan-activity; sid:100001347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.8.251.227"; classtype:trojan-activity; sid:100001348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.123.206.197"; classtype:trojan-activity; sid:100001349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.135.178.253"; classtype:trojan-activity; sid:100001350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.14.173.117"; classtype:trojan-activity; sid:100001351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.149.182.113"; classtype:trojan-activity; sid:100001352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.149.190.193"; classtype:trojan-activity; sid:100001353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.99"; classtype:trojan-activity; sid:100001354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.135"; classtype:trojan-activity; sid:100001355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.20"; classtype:trojan-activity; sid:100001356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.237"; classtype:trojan-activity; sid:100001357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.6"; classtype:trojan-activity; sid:100001358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.114.165"; classtype:trojan-activity; sid:100001359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.114.191"; classtype:trojan-activity; sid:100001360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.105"; classtype:trojan-activity; sid:100001361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.11"; classtype:trojan-activity; sid:100001362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.15"; classtype:trojan-activity; sid:100001363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.30"; classtype:trojan-activity; sid:100001364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.71"; classtype:trojan-activity; sid:100001365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.117.151"; classtype:trojan-activity; sid:100001366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.10"; classtype:trojan-activity; sid:100001367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.238"; classtype:trojan-activity; sid:100001368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.65"; classtype:trojan-activity; sid:100001369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.119.236"; classtype:trojan-activity; sid:100001370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.145"; classtype:trojan-activity; sid:100001371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.7"; classtype:trojan-activity; sid:100001372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.46"; classtype:trojan-activity; sid:100001373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.189.178.163"; classtype:trojan-activity; sid:100001374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.240.218.15"; classtype:trojan-activity; sid:100001375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.249.156.189"; classtype:trojan-activity; sid:100001376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.27.8.6"; classtype:trojan-activity; sid:100001377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.254.52"; classtype:trojan-activity; sid:100001378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.255.36"; classtype:trojan-activity; sid:100001379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.255.84"; classtype:trojan-activity; sid:100001380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.127.185.150"; classtype:trojan-activity; sid:100001381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.158.238.236"; classtype:trojan-activity; sid:100001382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.170.240.98"; classtype:trojan-activity; sid:100001383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.183.54.169"; classtype:trojan-activity; sid:100001384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.36.12.98"; classtype:trojan-activity; sid:100001385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"217.11.75.162"; classtype:trojan-activity; sid:100001386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"217.127.133.214"; classtype:trojan-activity; sid:100001387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.12.181.110"; classtype:trojan-activity; sid:100001388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.2.40.34"; classtype:trojan-activity; sid:100001389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.234.165.18"; classtype:trojan-activity; sid:100001390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.238.246.3"; classtype:trojan-activity; sid:100001391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.207.119"; classtype:trojan-activity; sid:100001392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.227.133"; classtype:trojan-activity; sid:100001393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.68.35"; classtype:trojan-activity; sid:100001394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.81.81"; classtype:trojan-activity; sid:100001395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.56.93.129"; classtype:trojan-activity; sid:100001396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.59.116.203"; classtype:trojan-activity; sid:100001397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.79.103.159"; classtype:trojan-activity; sid:100001398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.93.102.63"; classtype:trojan-activity; sid:100001399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.93.102.75"; classtype:trojan-activity; sid:100001400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.102.14"; classtype:trojan-activity; sid:100001401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.29.165"; classtype:trojan-activity; sid:100001402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.186.18"; classtype:trojan-activity; sid:100001403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.139.165"; classtype:trojan-activity; sid:100001404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.150.91"; classtype:trojan-activity; sid:100001405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.214.235"; classtype:trojan-activity; sid:100001406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.241.6.180"; classtype:trojan-activity; sid:100001407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.1.148"; classtype:trojan-activity; sid:100001408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.1.84"; classtype:trojan-activity; sid:100001409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.163.7"; classtype:trojan-activity; sid:100001410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.171.144"; classtype:trojan-activity; sid:100001411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.245.63"; classtype:trojan-activity; sid:100001412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.5.140"; classtype:trojan-activity; sid:100001413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.69.71.186"; classtype:trojan-activity; sid:100001414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.70.238.66"; classtype:trojan-activity; sid:100001415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.80.217.209"; classtype:trojan-activity; sid:100001416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.85.145.194"; classtype:trojan-activity; sid:100001417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"21robo.com"; classtype:trojan-activity; sid:100001418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.118.168.155"; classtype:trojan-activity; sid:100001419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.126.237.74"; classtype:trojan-activity; sid:100001420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.200.22.163"; classtype:trojan-activity; sid:100001421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.71.239.115"; classtype:trojan-activity; sid:100001422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.1.144.183"; classtype:trojan-activity; sid:100001423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.124.78.15"; classtype:trojan-activity; sid:100001424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.125.69"; classtype:trojan-activity; sid:100001425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.136.213"; classtype:trojan-activity; sid:100001426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.202.232.230"; classtype:trojan-activity; sid:100001427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.130.147"; classtype:trojan-activity; sid:100001428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.251.109"; classtype:trojan-activity; sid:100001429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.116.167"; classtype:trojan-activity; sid:100001430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.172.207"; classtype:trojan-activity; sid:100001431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.184.31"; classtype:trojan-activity; sid:100001432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.252.64"; classtype:trojan-activity; sid:100001433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.8.64"; classtype:trojan-activity; sid:100001434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.232.1.82"; classtype:trojan-activity; sid:100001435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.235.137.36"; classtype:trojan-activity; sid:100001436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.112.125"; classtype:trojan-activity; sid:100001437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.32.88"; classtype:trojan-activity; sid:100001438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.34.43"; classtype:trojan-activity; sid:100001439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.43.223"; classtype:trojan-activity; sid:100001440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.68.16"; classtype:trojan-activity; sid:100001441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.108.17.64"; classtype:trojan-activity; sid:100001442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.118.248.149"; classtype:trojan-activity; sid:100001443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.119.65.145"; classtype:trojan-activity; sid:100001444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.132.125.138"; classtype:trojan-activity; sid:100001445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.103.120"; classtype:trojan-activity; sid:100001446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.9.5"; classtype:trojan-activity; sid:100001447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.148.192"; classtype:trojan-activity; sid:100001448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.211.78"; classtype:trojan-activity; sid:100001449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.17.132"; classtype:trojan-activity; sid:100001450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.237.155"; classtype:trojan-activity; sid:100001451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.17.245"; classtype:trojan-activity; sid:100001452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.179.215.189"; classtype:trojan-activity; sid:100001453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.185.116.233"; classtype:trojan-activity; sid:100001454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.186.20.19"; classtype:trojan-activity; sid:100001455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.187.9.178"; classtype:trojan-activity; sid:100001456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.211.72.66"; classtype:trojan-activity; sid:100001457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.236.85.220"; classtype:trojan-activity; sid:100001458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.238.230.7"; classtype:trojan-activity; sid:100001459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.239.83.232"; classtype:trojan-activity; sid:100001460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.248.64.253"; classtype:trojan-activity; sid:100001461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.92.9.126"; classtype:trojan-activity; sid:100001462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.95.190.20"; classtype:trojan-activity; sid:100001463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.99.171.192"; classtype:trojan-activity; sid:100001464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.131.201.82"; classtype:trojan-activity; sid:100001465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.166.117.210"; classtype:trojan-activity; sid:100001466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.167.118.17"; classtype:trojan-activity; sid:100001467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.225.68"; classtype:trojan-activity; sid:100001468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.234.84"; classtype:trojan-activity; sid:100001469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.5.29"; classtype:trojan-activity; sid:100001470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.73.175"; classtype:trojan-activity; sid:100001471; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.115.118.232"; classtype:trojan-activity; sid:100001472; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.125.186.135"; classtype:trojan-activity; sid:100001473; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.126.120.25"; classtype:trojan-activity; sid:100001474; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.228.143.58"; classtype:trojan-activity; sid:100001475; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.24.213.121"; classtype:trojan-activity; sid:100001476; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.149.13"; classtype:trojan-activity; sid:100001477; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.21.167"; classtype:trojan-activity; sid:100001478; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.95.89.21"; classtype:trojan-activity; sid:100001479; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.103.74.180"; classtype:trojan-activity; sid:100001480; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.11.141.134"; classtype:trojan-activity; sid:100001481; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.119.158.74"; classtype:trojan-activity; sid:100001482; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.137.147.95"; classtype:trojan-activity; sid:100001483; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.137.233.132"; classtype:trojan-activity; sid:100001484; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.152.235.88"; classtype:trojan-activity; sid:100001485; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.158.25.98"; classtype:trojan-activity; sid:100001486; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.176.206.12"; classtype:trojan-activity; sid:100001487; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.184.1.41"; classtype:trojan-activity; sid:100001488; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.192.191.109"; classtype:trojan-activity; sid:100001489; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.225.114.161"; classtype:trojan-activity; sid:100001490; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.227.190.78"; classtype:trojan-activity; sid:100001491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.35.245.52"; classtype:trojan-activity; sid:100001492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.39.181.18"; classtype:trojan-activity; sid:100001493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.39.34.242"; classtype:trojan-activity; sid:100001494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.42.229.143"; classtype:trojan-activity; sid:100001495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.45.4.1"; classtype:trojan-activity; sid:100001496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.51.91.113"; classtype:trojan-activity; sid:100001497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.53.163.10"; classtype:trojan-activity; sid:100001498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.53.163.9"; classtype:trojan-activity; sid:100001499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.89.140.190"; classtype:trojan-activity; sid:100001500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.1.245.16"; classtype:trojan-activity; sid:100001501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.1.245.7"; classtype:trojan-activity; sid:100001502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.105.106.201"; classtype:trojan-activity; sid:100001503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.105.152.107"; classtype:trojan-activity; sid:100001504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.116.84.57"; classtype:trojan-activity; sid:100001505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.14.211.219"; classtype:trojan-activity; sid:100001506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.14.81.201"; classtype:trojan-activity; sid:100001507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.141.218.17"; classtype:trojan-activity; sid:100001508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.147.29.52"; classtype:trojan-activity; sid:100001509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.147.40.128"; classtype:trojan-activity; sid:100001510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.184.251.135"; classtype:trojan-activity; sid:100001511; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.193.196.190"; classtype:trojan-activity; sid:100001512; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.193.217.210"; classtype:trojan-activity; sid:100001513; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.149.142"; classtype:trojan-activity; sid:100001514; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.159.98"; classtype:trojan-activity; sid:100001515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.192.66"; classtype:trojan-activity; sid:100001516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.210.20"; classtype:trojan-activity; sid:100001517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.22.217"; classtype:trojan-activity; sid:100001518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.23.215"; classtype:trojan-activity; sid:100001519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.232.65"; classtype:trojan-activity; sid:100001520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.3.194"; classtype:trojan-activity; sid:100001521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.34.48"; classtype:trojan-activity; sid:100001522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.110.211"; classtype:trojan-activity; sid:100001523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.140.229"; classtype:trojan-activity; sid:100001524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.32.146"; classtype:trojan-activity; sid:100001525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.201.183.149"; classtype:trojan-activity; sid:100001526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.202.182.201"; classtype:trojan-activity; sid:100001527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.102.12"; classtype:trojan-activity; sid:100001528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.116.86"; classtype:trojan-activity; sid:100001529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.154.105"; classtype:trojan-activity; sid:100001530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.165.138"; classtype:trojan-activity; sid:100001531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.185.42"; classtype:trojan-activity; sid:100001532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.213.79"; classtype:trojan-activity; sid:100001533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.255.42"; classtype:trojan-activity; sid:100001534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.28.115"; classtype:trojan-activity; sid:100001535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.4.188"; classtype:trojan-activity; sid:100001536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.68.144"; classtype:trojan-activity; sid:100001537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.7.141"; classtype:trojan-activity; sid:100001538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.87.75"; classtype:trojan-activity; sid:100001539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.94.134"; classtype:trojan-activity; sid:100001540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.204.253.74"; classtype:trojan-activity; sid:100001541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.205.178.110"; classtype:trojan-activity; sid:100001542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.136.101"; classtype:trojan-activity; sid:100001543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.154.122"; classtype:trojan-activity; sid:100001544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.80.209"; classtype:trojan-activity; sid:100001545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.151.126"; classtype:trojan-activity; sid:100001546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.155.31"; classtype:trojan-activity; sid:100001547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.170.203"; classtype:trojan-activity; sid:100001548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.119.27"; classtype:trojan-activity; sid:100001549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.164.18"; classtype:trojan-activity; sid:100001550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.237.105"; classtype:trojan-activity; sid:100001551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.247.130"; classtype:trojan-activity; sid:100001552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.25.59"; classtype:trojan-activity; sid:100001553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.34.2"; classtype:trojan-activity; sid:100001554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.92.64"; classtype:trojan-activity; sid:100001555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.208.122"; classtype:trojan-activity; sid:100001556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.231.15"; classtype:trojan-activity; sid:100001557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.107.125"; classtype:trojan-activity; sid:100001558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.234.28"; classtype:trojan-activity; sid:100001559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.236.134"; classtype:trojan-activity; sid:100001560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.32.122"; classtype:trojan-activity; sid:100001561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.44.19"; classtype:trojan-activity; sid:100001562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.63.243"; classtype:trojan-activity; sid:100001563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.104.201"; classtype:trojan-activity; sid:100001564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.109.105"; classtype:trojan-activity; sid:100001565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.175.208"; classtype:trojan-activity; sid:100001566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.255.202"; classtype:trojan-activity; sid:100001567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.66.112"; classtype:trojan-activity; sid:100001568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.84.74"; classtype:trojan-activity; sid:100001569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.214.37.129"; classtype:trojan-activity; sid:100001570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.139.242"; classtype:trojan-activity; sid:100001571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.190.172"; classtype:trojan-activity; sid:100001572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.212.209"; classtype:trojan-activity; sid:100001573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.253.149"; classtype:trojan-activity; sid:100001574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.71.243"; classtype:trojan-activity; sid:100001575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.98.242"; classtype:trojan-activity; sid:100001576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.117.54"; classtype:trojan-activity; sid:100001577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.128.156"; classtype:trojan-activity; sid:100001578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.131.66"; classtype:trojan-activity; sid:100001579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.144.66"; classtype:trojan-activity; sid:100001580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.197.193"; classtype:trojan-activity; sid:100001581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.225.28"; classtype:trojan-activity; sid:100001582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.227.95"; classtype:trojan-activity; sid:100001583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.234.98"; classtype:trojan-activity; sid:100001584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.133.53"; classtype:trojan-activity; sid:100001585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.191.58"; classtype:trojan-activity; sid:100001586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.248.121"; classtype:trojan-activity; sid:100001587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.132.71"; classtype:trojan-activity; sid:100001588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.151.83"; classtype:trojan-activity; sid:100001589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.160.112"; classtype:trojan-activity; sid:100001590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.176.72"; classtype:trojan-activity; sid:100001591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.192.223"; classtype:trojan-activity; sid:100001592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.83.244"; classtype:trojan-activity; sid:100001593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.20.66"; classtype:trojan-activity; sid:100001594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.249.0"; classtype:trojan-activity; sid:100001595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.85.168"; classtype:trojan-activity; sid:100001596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.221.239.223"; classtype:trojan-activity; sid:100001597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.241.223"; classtype:trojan-activity; sid:100001598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.76.80"; classtype:trojan-activity; sid:100001599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.223.242.164"; classtype:trojan-activity; sid:100001600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.24.28.134"; classtype:trojan-activity; sid:100001601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.129.198"; classtype:trojan-activity; sid:100001602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.154.13"; classtype:trojan-activity; sid:100001603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.212.124"; classtype:trojan-activity; sid:100001604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.58.5"; classtype:trojan-activity; sid:100001605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.43.117.98"; classtype:trojan-activity; sid:100001606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.0.98.131"; classtype:trojan-activity; sid:100001607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.11.51.57"; classtype:trojan-activity; sid:100001608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.13.23.180"; classtype:trojan-activity; sid:100001609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.124.130"; classtype:trojan-activity; sid:100001610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.179.83"; classtype:trojan-activity; sid:100001611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.184.59"; classtype:trojan-activity; sid:100001612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.191.243"; classtype:trojan-activity; sid:100001613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.194.67"; classtype:trojan-activity; sid:100001614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.216.132"; classtype:trojan-activity; sid:100001615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.219.28"; classtype:trojan-activity; sid:100001616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.24.115"; classtype:trojan-activity; sid:100001617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.30.65"; classtype:trojan-activity; sid:100001618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.63.203"; classtype:trojan-activity; sid:100001619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.65.233"; classtype:trojan-activity; sid:100001620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.79.66"; classtype:trojan-activity; sid:100001621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.94.16"; classtype:trojan-activity; sid:100001622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.179.201.26"; classtype:trojan-activity; sid:100001623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.195.84.250"; classtype:trojan-activity; sid:100001624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.177"; classtype:trojan-activity; sid:100001625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.69"; classtype:trojan-activity; sid:100001626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.28.7.159"; classtype:trojan-activity; sid:100001627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.30.119.23"; classtype:trojan-activity; sid:100001628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32.208.157.193"; classtype:trojan-activity; sid:100001629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32792.prolocksmithwinterpark.com"; classtype:trojan-activity; sid:100001630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"35.184.169.169"; classtype:trojan-activity; sid:100001631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.108.231.218"; classtype:trojan-activity; sid:100001632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.248.228.64"; classtype:trojan-activity; sid:100001633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.248.83.98"; classtype:trojan-activity; sid:100001634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.250.203.246"; classtype:trojan-activity; sid:100001635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.157.225"; classtype:trojan-activity; sid:100001636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.18.18"; classtype:trojan-activity; sid:100001637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.51.244"; classtype:trojan-activity; sid:100001638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.255.90.219"; classtype:trojan-activity; sid:100001639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.33.128.58"; classtype:trojan-activity; sid:100001640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.33.160.167"; classtype:trojan-activity; sid:100001641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.34.150.236"; classtype:trojan-activity; sid:100001642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.105.159"; classtype:trojan-activity; sid:100001643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.133.125"; classtype:trojan-activity; sid:100001644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.139.36"; classtype:trojan-activity; sid:100001645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.89.18.133"; classtype:trojan-activity; sid:100001646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360.lcy2zzx.pw"; classtype:trojan-activity; sid:100001647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360down7.miiyun.cn"; classtype:trojan-activity; sid:100001648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.222.98.51"; classtype:trojan-activity; sid:100001649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.233.60.68"; classtype:trojan-activity; sid:100001650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.179.221"; classtype:trojan-activity; sid:100001651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.180.172"; classtype:trojan-activity; sid:100001652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.44.238.35"; classtype:trojan-activity; sid:100001653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.49.230.177"; classtype:trojan-activity; sid:100001654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.14.36"; classtype:trojan-activity; sid:100001655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.14.52"; classtype:trojan-activity; sid:100001656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.230.61"; classtype:trojan-activity; sid:100001657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"38.77.14.237"; classtype:trojan-activity; sid:100001658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.245.254"; classtype:trojan-activity; sid:100001659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.98.136"; classtype:trojan-activity; sid:100001660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.117.31.162"; classtype:trojan-activity; sid:100001661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.162.104.119"; classtype:trojan-activity; sid:100001662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.196.34"; classtype:trojan-activity; sid:100001663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.59.160"; classtype:trojan-activity; sid:100001664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.66.44.109"; classtype:trojan-activity; sid:100001665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.104.83"; classtype:trojan-activity; sid:100001666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.125.186"; classtype:trojan-activity; sid:100001667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.146.60"; classtype:trojan-activity; sid:100001668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.148.163"; classtype:trojan-activity; sid:100001669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.206.228"; classtype:trojan-activity; sid:100001670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.124.76"; classtype:trojan-activity; sid:100001671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.171.125"; classtype:trojan-activity; sid:100001672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.249.255"; classtype:trojan-activity; sid:100001673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.60.61"; classtype:trojan-activity; sid:100001674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.167.202"; classtype:trojan-activity; sid:100001675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.67.64"; classtype:trojan-activity; sid:100001676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.10.198"; classtype:trojan-activity; sid:100001677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.163.231"; classtype:trojan-activity; sid:100001678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.168.234"; classtype:trojan-activity; sid:100001679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.203.225"; classtype:trojan-activity; sid:100001680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.237.84"; classtype:trojan-activity; sid:100001681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.132.170"; classtype:trojan-activity; sid:100001682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.194.65"; classtype:trojan-activity; sid:100001683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.235.122"; classtype:trojan-activity; sid:100001684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.33.191"; classtype:trojan-activity; sid:100001685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.78.251"; classtype:trojan-activity; sid:100001686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.113.201"; classtype:trojan-activity; sid:100001687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.114.45"; classtype:trojan-activity; sid:100001688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.14.27"; classtype:trojan-activity; sid:100001689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.150.203"; classtype:trojan-activity; sid:100001690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.197.81"; classtype:trojan-activity; sid:100001691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.209.209"; classtype:trojan-activity; sid:100001692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.48.213"; classtype:trojan-activity; sid:100001693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.63.152"; classtype:trojan-activity; sid:100001694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.94.189"; classtype:trojan-activity; sid:100001695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.163.188"; classtype:trojan-activity; sid:100001696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.166.31"; classtype:trojan-activity; sid:100001697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.218.46"; classtype:trojan-activity; sid:100001698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.91.244"; classtype:trojan-activity; sid:100001699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.93.171"; classtype:trojan-activity; sid:100001700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.127.214"; classtype:trojan-activity; sid:100001701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.18.140"; classtype:trojan-activity; sid:100001702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.191.137"; classtype:trojan-activity; sid:100001703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.205.255"; classtype:trojan-activity; sid:100001704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.24.54"; classtype:trojan-activity; sid:100001705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.36.151"; classtype:trojan-activity; sid:100001706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.37.182"; classtype:trojan-activity; sid:100001707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.251.0"; classtype:trojan-activity; sid:100001708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.27.15"; classtype:trojan-activity; sid:100001709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.29.231"; classtype:trojan-activity; sid:100001710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.70.88"; classtype:trojan-activity; sid:100001711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.83.94.11"; classtype:trojan-activity; sid:100001712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.115.152"; classtype:trojan-activity; sid:100001713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.85.54.4"; classtype:trojan-activity; sid:100001714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.129.233"; classtype:trojan-activity; sid:100001715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.170.209"; classtype:trojan-activity; sid:100001716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.211.20"; classtype:trojan-activity; sid:100001717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.234.187"; classtype:trojan-activity; sid:100001718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.63.58"; classtype:trojan-activity; sid:100001719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.93.109"; classtype:trojan-activity; sid:100001720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.155.96"; classtype:trojan-activity; sid:100001721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.233.131"; classtype:trojan-activity; sid:100001722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.67.238"; classtype:trojan-activity; sid:100001723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.72.9"; classtype:trojan-activity; sid:100001724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.108.109"; classtype:trojan-activity; sid:100001725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.145.11"; classtype:trojan-activity; sid:100001726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.146.198"; classtype:trojan-activity; sid:100001727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.63.23"; classtype:trojan-activity; sid:100001728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.90.86.212"; classtype:trojan-activity; sid:100001729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"40.88.2.151"; classtype:trojan-activity; sid:100001730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.139.209.46"; classtype:trojan-activity; sid:100001731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.165.130.43"; classtype:trojan-activity; sid:100001732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.190.63.174"; classtype:trojan-activity; sid:100001733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.193.192.100"; classtype:trojan-activity; sid:100001734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.219.185.171"; classtype:trojan-activity; sid:100001735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.226.60.115"; classtype:trojan-activity; sid:100001736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.72.203.82"; classtype:trojan-activity; sid:100001737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.133"; classtype:trojan-activity; sid:100001738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.27"; classtype:trojan-activity; sid:100001739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.197"; classtype:trojan-activity; sid:100001740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.202.101.199"; classtype:trojan-activity; sid:100001741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.39.211"; classtype:trojan-activity; sid:100001742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.43.161"; classtype:trojan-activity; sid:100001743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.65.104"; classtype:trojan-activity; sid:100001744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.82.176"; classtype:trojan-activity; sid:100001745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.232.81.179"; classtype:trojan-activity; sid:100001746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.180.147"; classtype:trojan-activity; sid:100001747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.239.26.122"; classtype:trojan-activity; sid:100001748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.56.15.227"; classtype:trojan-activity; sid:100001749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.61.99.155"; classtype:trojan-activity; sid:100001750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.82.217.241"; classtype:trojan-activity; sid:100001751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.84.37.198"; classtype:trojan-activity; sid:100001752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.241.106.183"; classtype:trojan-activity; sid:100001753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.241.108.134"; classtype:trojan-activity; sid:100001754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.252.8.94"; classtype:trojan-activity; sid:100001755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.115.172.148"; classtype:trojan-activity; sid:100001756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.1.242"; classtype:trojan-activity; sid:100001757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.203.192"; classtype:trojan-activity; sid:100001758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.135.134.228"; classtype:trojan-activity; sid:100001759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.182"; classtype:trojan-activity; sid:100001760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.204"; classtype:trojan-activity; sid:100001761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.141.84.182"; classtype:trojan-activity; sid:100001762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.141.84.184"; classtype:trojan-activity; sid:100001763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.118"; classtype:trojan-activity; sid:100001764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.135"; classtype:trojan-activity; sid:100001765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.139"; classtype:trojan-activity; sid:100001766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.196"; classtype:trojan-activity; sid:100001767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.213"; classtype:trojan-activity; sid:100001768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.242"; classtype:trojan-activity; sid:100001769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.27"; classtype:trojan-activity; sid:100001770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.65"; classtype:trojan-activity; sid:100001771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.47"; classtype:trojan-activity; sid:100001772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.94"; classtype:trojan-activity; sid:100001773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.164.140.130"; classtype:trojan-activity; sid:100001774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.165.215.19"; classtype:trojan-activity; sid:100001775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.151"; classtype:trojan-activity; sid:100001776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.22"; classtype:trojan-activity; sid:100001777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.248"; classtype:trojan-activity; sid:100001778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.110.99"; classtype:trojan-activity; sid:100001779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.22.209.58"; classtype:trojan-activity; sid:100001780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.229.53.115"; classtype:trojan-activity; sid:100001781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.23.22.186"; classtype:trojan-activity; sid:100001782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.248.194.48"; classtype:trojan-activity; sid:100001783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.27.253.137"; classtype:trojan-activity; sid:100001784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.51.104.59"; classtype:trojan-activity; sid:100001785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.6.24.251"; classtype:trojan-activity; sid:100001786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.81.235.31"; classtype:trojan-activity; sid:100001787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.85.90.203"; classtype:trojan-activity; sid:100001788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.9.148.37"; classtype:trojan-activity; sid:100001789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.92.108.125"; classtype:trojan-activity; sid:100001790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.117.42.29"; classtype:trojan-activity; sid:100001791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.172.75.231"; classtype:trojan-activity; sid:100001792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.182.173.246"; classtype:trojan-activity; sid:100001793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.20.63.218"; classtype:trojan-activity; sid:100001794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.214.27.4"; classtype:trojan-activity; sid:100001795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.24.130.254"; classtype:trojan-activity; sid:100001796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.241.120.165"; classtype:trojan-activity; sid:100001797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.243.179.115"; classtype:trojan-activity; sid:100001798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.249.33.79"; classtype:trojan-activity; sid:100001799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.25.242.211"; classtype:trojan-activity; sid:100001800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.118.86"; classtype:trojan-activity; sid:100001801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.86.128"; classtype:trojan-activity; sid:100001802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.97.76.242"; classtype:trojan-activity; sid:100001803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.103.219.77"; classtype:trojan-activity; sid:100001804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.145.152.26"; classtype:trojan-activity; sid:100001805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.151.23.172"; classtype:trojan-activity; sid:100001806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.157.97.71"; classtype:trojan-activity; sid:100001807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.16.131.51"; classtype:trojan-activity; sid:100001808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.21.202.98"; classtype:trojan-activity; sid:100001809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.46.231.38"; classtype:trojan-activity; sid:100001810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.119.187.230"; classtype:trojan-activity; sid:100001811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.162.113"; classtype:trojan-activity; sid:100001812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.87.36"; classtype:trojan-activity; sid:100001813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.143.43.93"; classtype:trojan-activity; sid:100001814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.156.35.166"; classtype:trojan-activity; sid:100001815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.158.201.200"; classtype:trojan-activity; sid:100001816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.20.121"; classtype:trojan-activity; sid:100001817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.21.3"; classtype:trojan-activity; sid:100001818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.174.182.99"; classtype:trojan-activity; sid:100001819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.170.49"; classtype:trojan-activity; sid:100001820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.178.183"; classtype:trojan-activity; sid:100001821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.179.129"; classtype:trojan-activity; sid:100001822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.68.221.252"; classtype:trojan-activity; sid:100001823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.188.62.111"; classtype:trojan-activity; sid:100001824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.2.70.50"; classtype:trojan-activity; sid:100001825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.53.146.179"; classtype:trojan-activity; sid:100001826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.79.75.210"; classtype:trojan-activity; sid:100001827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.95.226.154"; classtype:trojan-activity; sid:100001828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.115.174.102"; classtype:trojan-activity; sid:100001829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.115.174.106"; classtype:trojan-activity; sid:100001830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.121.91.255"; classtype:trojan-activity; sid:100001831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.252.47.29"; classtype:trojan-activity; sid:100001832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.114.136"; classtype:trojan-activity; sid:100001833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.180.122"; classtype:trojan-activity; sid:100001834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.114.246.26"; classtype:trojan-activity; sid:100001835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.162.92"; classtype:trojan-activity; sid:100001836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.174.4"; classtype:trojan-activity; sid:100001837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.125.191.4"; classtype:trojan-activity; sid:100001838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.126.247.118"; classtype:trojan-activity; sid:100001839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.141.122.109"; classtype:trojan-activity; sid:100001840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.166.120"; classtype:trojan-activity; sid:100001841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.200.124"; classtype:trojan-activity; sid:100001842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.143.189.75"; classtype:trojan-activity; sid:100001843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.218.67.253"; classtype:trojan-activity; sid:100001844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.22.212.107"; classtype:trojan-activity; sid:100001845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.226.129.29"; classtype:trojan-activity; sid:100001846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.230.89.42"; classtype:trojan-activity; sid:100001847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.238.42.192"; classtype:trojan-activity; sid:100001848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.240.147.97"; classtype:trojan-activity; sid:100001849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.241.78.55"; classtype:trojan-activity; sid:100001850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.243.126.133"; classtype:trojan-activity; sid:100001851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.243.208.225"; classtype:trojan-activity; sid:100001852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.142.227"; classtype:trojan-activity; sid:100001853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.79.174"; classtype:trojan-activity; sid:100001854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.84.131"; classtype:trojan-activity; sid:100001855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.48.154.143"; classtype:trojan-activity; sid:100001856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.153"; classtype:trojan-activity; sid:100001857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.39"; classtype:trojan-activity; sid:100001858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.76.151.51"; classtype:trojan-activity; sid:100001859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.97.206.33"; classtype:trojan-activity; sid:100001860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.0.211.161"; classtype:trojan-activity; sid:100001861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.102.168.189"; classtype:trojan-activity; sid:100001862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.202.3"; classtype:trojan-activity; sid:100001863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.214.4"; classtype:trojan-activity; sid:100001864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.237.51"; classtype:trojan-activity; sid:100001865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.246.125"; classtype:trojan-activity; sid:100001866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.23.114.97"; classtype:trojan-activity; sid:100001867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.58.117.226"; classtype:trojan-activity; sid:100001868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.18.144"; classtype:trojan-activity; sid:100001869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.96.37.124"; classtype:trojan-activity; sid:100001870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.169.237"; classtype:trojan-activity; sid:100001871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.10.91.242"; classtype:trojan-activity; sid:100001872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.13.61.12"; classtype:trojan-activity; sid:100001873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.164.130.220"; classtype:trojan-activity; sid:100001874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.175.124.27"; classtype:trojan-activity; sid:100001875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.20.217.142"; classtype:trojan-activity; sid:100001876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.208.135.42"; classtype:trojan-activity; sid:100001877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.122.57"; classtype:trojan-activity; sid:100001878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.186.185"; classtype:trojan-activity; sid:100001879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.216.23"; classtype:trojan-activity; sid:100001880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.233.94"; classtype:trojan-activity; sid:100001881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.6.112"; classtype:trojan-activity; sid:100001882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.100.83"; classtype:trojan-activity; sid:100001883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.111.39"; classtype:trojan-activity; sid:100001884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.202.218"; classtype:trojan-activity; sid:100001885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.206.246"; classtype:trojan-activity; sid:100001886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.218.31"; classtype:trojan-activity; sid:100001887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.220.167"; classtype:trojan-activity; sid:100001888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.254.178"; classtype:trojan-activity; sid:100001889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.162.59"; classtype:trojan-activity; sid:100001890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.83.55"; classtype:trojan-activity; sid:100001891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.195.111"; classtype:trojan-activity; sid:100001892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.177.196"; classtype:trojan-activity; sid:100001893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.86.208"; classtype:trojan-activity; sid:100001894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.223.84.102"; classtype:trojan-activity; sid:100001895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.15.104"; classtype:trojan-activity; sid:100001896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.4.72"; classtype:trojan-activity; sid:100001897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.51.127"; classtype:trojan-activity; sid:100001898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.60.174"; classtype:trojan-activity; sid:100001899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.8.81"; classtype:trojan-activity; sid:100001900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.26.104.150"; classtype:trojan-activity; sid:100001901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.10.121"; classtype:trojan-activity; sid:100001902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.8.43"; classtype:trojan-activity; sid:100001903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.99.254"; classtype:trojan-activity; sid:100001904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.164.96.98"; classtype:trojan-activity; sid:100001905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.91.194"; classtype:trojan-activity; sid:100001906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.247.224.66"; classtype:trojan-activity; sid:100001907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.253.94.230"; classtype:trojan-activity; sid:100001908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.41.230.161"; classtype:trojan-activity; sid:100001909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.47.220.169"; classtype:trojan-activity; sid:100001910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.103.217"; classtype:trojan-activity; sid:100001911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.199.47"; classtype:trojan-activity; sid:100001912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.30.172"; classtype:trojan-activity; sid:100001913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.9.166"; classtype:trojan-activity; sid:100001914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.99.161"; classtype:trojan-activity; sid:100001915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.117.237"; classtype:trojan-activity; sid:100001916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.89.220"; classtype:trojan-activity; sid:100001917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.103.56"; classtype:trojan-activity; sid:100001918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.64.63"; classtype:trojan-activity; sid:100001919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.69.77"; classtype:trojan-activity; sid:100001920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.180.67"; classtype:trojan-activity; sid:100001921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.181.7"; classtype:trojan-activity; sid:100001922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.57.96.116"; classtype:trojan-activity; sid:100001923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.170.60"; classtype:trojan-activity; sid:100001924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.73.220"; classtype:trojan-activity; sid:100001925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.61.218.23"; classtype:trojan-activity; sid:100001926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.65.172.121"; classtype:trojan-activity; sid:100001927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.0.22"; classtype:trojan-activity; sid:100001928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.104.46"; classtype:trojan-activity; sid:100001929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.110.59"; classtype:trojan-activity; sid:100001930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.195"; classtype:trojan-activity; sid:100001931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.86"; classtype:trojan-activity; sid:100001932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.255.60"; classtype:trojan-activity; sid:100001933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.45.130"; classtype:trojan-activity; sid:100001934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.98.144.75"; classtype:trojan-activity; sid:100001935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.1.98.131"; classtype:trojan-activity; sid:100001936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.141.73.58"; classtype:trojan-activity; sid:100001937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.131.205"; classtype:trojan-activity; sid:100001938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.143.46"; classtype:trojan-activity; sid:100001939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.155.61"; classtype:trojan-activity; sid:100001940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.227.31"; classtype:trojan-activity; sid:100001941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.31.126.33"; classtype:trojan-activity; sid:100001942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.149.66"; classtype:trojan-activity; sid:100001943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.222.98"; classtype:trojan-activity; sid:100001944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.43.207.148"; classtype:trojan-activity; sid:100001945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.90.165.236"; classtype:trojan-activity; sid:100001946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"63.245.122.93"; classtype:trojan-activity; sid:100001947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"64.233.154.99"; classtype:trojan-activity; sid:100001948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.125.128.196"; classtype:trojan-activity; sid:100001949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.21.58.252"; classtype:trojan-activity; sid:100001950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.26.155.131"; classtype:trojan-activity; sid:100001951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.35.61.255"; classtype:trojan-activity; sid:100001952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.229.214.115"; classtype:trojan-activity; sid:100001953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.57.55.210"; classtype:trojan-activity; sid:100001954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.74.7.197"; classtype:trojan-activity; sid:100001955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.97.181.196"; classtype:trojan-activity; sid:100001956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.245.151.203"; classtype:trojan-activity; sid:100001957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.3.169.223"; classtype:trojan-activity; sid:100001958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.8.138.101"; classtype:trojan-activity; sid:100001959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.83.49.234"; classtype:trojan-activity; sid:100001960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.84.138.165"; classtype:trojan-activity; sid:100001961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.148.103.248"; classtype:trojan-activity; sid:100001962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.151.244.128"; classtype:trojan-activity; sid:100001963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.174.182.226"; classtype:trojan-activity; sid:100001964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.175.107.153"; classtype:trojan-activity; sid:100001965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.188.144.143"; classtype:trojan-activity; sid:100001966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.204.88.29"; classtype:trojan-activity; sid:100001967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.106.84"; classtype:trojan-activity; sid:100001968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.119.241"; classtype:trojan-activity; sid:100001969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.78.33.33"; classtype:trojan-activity; sid:100001970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.115.37.205"; classtype:trojan-activity; sid:100001971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.120.237.255"; classtype:trojan-activity; sid:100001972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.123.245.151"; classtype:trojan-activity; sid:100001973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.124.231.110"; classtype:trojan-activity; sid:100001974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.127.214.47"; classtype:trojan-activity; sid:100001975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.146.232.34"; classtype:trojan-activity; sid:100001976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.165.173.49"; classtype:trojan-activity; sid:100001977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.196.158.227"; classtype:trojan-activity; sid:100001978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.222.157.166"; classtype:trojan-activity; sid:100001979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.229.0.133"; classtype:trojan-activity; sid:100001980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.63.73.234"; classtype:trojan-activity; sid:100001981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.115.194"; classtype:trojan-activity; sid:100001982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.227.186"; classtype:trojan-activity; sid:100001983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.76.240.206"; classtype:trojan-activity; sid:100001984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.115.31.30"; classtype:trojan-activity; sid:100001985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.118.240.88"; classtype:trojan-activity; sid:100001986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.167.10.180"; classtype:trojan-activity; sid:100001987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.236.190.250"; classtype:trojan-activity; sid:100001988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.25.5.105"; classtype:trojan-activity; sid:100001989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.93.129.118"; classtype:trojan-activity; sid:100001990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.127.148.69"; classtype:trojan-activity; sid:100001991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.146.190.91"; classtype:trojan-activity; sid:100001992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.204.63.239"; classtype:trojan-activity; sid:100001993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.29.48.164"; classtype:trojan-activity; sid:100001994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.34.191.213"; classtype:trojan-activity; sid:100001995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.40.234.166"; classtype:trojan-activity; sid:100001996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.106.142"; classtype:trojan-activity; sid:100001997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.2.122"; classtype:trojan-activity; sid:100001998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.235.106"; classtype:trojan-activity; sid:100001999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.47.133.58"; classtype:trojan-activity; sid:100002000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.71.60.69"; classtype:trojan-activity; sid:100002001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.85.106.211"; classtype:trojan-activity; sid:100002002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.17.22.30"; classtype:trojan-activity; sid:100002003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.186.139.38"; classtype:trojan-activity; sid:100002004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.180.98"; classtype:trojan-activity; sid:100002005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.200.62"; classtype:trojan-activity; sid:100002006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.202.249.109"; classtype:trojan-activity; sid:100002007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.214.69.226"; classtype:trojan-activity; sid:100002008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.229.230.118"; classtype:trojan-activity; sid:100002009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.31.40.122"; classtype:trojan-activity; sid:100002010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.204.216.103"; classtype:trojan-activity; sid:100002011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.70.164.42"; classtype:trojan-activity; sid:100002012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.101.1.159"; classtype:trojan-activity; sid:100002013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.108.224.112"; classtype:trojan-activity; sid:100002014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.194.117.165"; classtype:trojan-activity; sid:100002015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.195.115.176"; classtype:trojan-activity; sid:100002016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.199.84.77"; classtype:trojan-activity; sid:100002017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.64.139.223"; classtype:trojan-activity; sid:100002018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.75.165.81"; classtype:trojan-activity; sid:100002019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.127.141.52"; classtype:trojan-activity; sid:100002020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.83.102.27"; classtype:trojan-activity; sid:100002021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.99.213.61"; classtype:trojan-activity; sid:100002022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.170.11.82"; classtype:trojan-activity; sid:100002023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.178.22.145"; classtype:trojan-activity; sid:100002024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.217.92.231"; classtype:trojan-activity; sid:100002025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.250.199.133"; classtype:trojan-activity; sid:100002026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.254.129.227"; classtype:trojan-activity; sid:100002027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.84.134.33"; classtype:trojan-activity; sid:100002028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.95.12.137"; classtype:trojan-activity; sid:100002029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.111.182.31"; classtype:trojan-activity; sid:100002030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.237.25.210"; classtype:trojan-activity; sid:100002031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.50.153"; classtype:trojan-activity; sid:100002032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.52.220"; classtype:trojan-activity; sid:100002033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.89.203.238"; classtype:trojan-activity; sid:100002034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77st.net"; classtype:trojan-activity; sid:100002035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.145.224.45"; classtype:trojan-activity; sid:100002036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.186.155.18"; classtype:trojan-activity; sid:100002037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.141.144"; classtype:trojan-activity; sid:100002038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.240.125"; classtype:trojan-activity; sid:100002039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.41.200"; classtype:trojan-activity; sid:100002040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.168.64"; classtype:trojan-activity; sid:100002041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.188.141"; classtype:trojan-activity; sid:100002042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.104.157"; classtype:trojan-activity; sid:100002043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.176.163"; classtype:trojan-activity; sid:100002044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.27.157"; classtype:trojan-activity; sid:100002045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.23.172.81"; classtype:trojan-activity; sid:100002046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.8.225.77"; classtype:trojan-activity; sid:100002047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.11.195.121"; classtype:trojan-activity; sid:100002048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.13.49.221"; classtype:trojan-activity; sid:100002049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.130.253.13"; classtype:trojan-activity; sid:100002050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.147.123.48"; classtype:trojan-activity; sid:100002051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.175.42.244"; classtype:trojan-activity; sid:100002052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.21.84.63"; classtype:trojan-activity; sid:100002053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.7.170.58"; classtype:trojan-activity; sid:100002054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.79.58.94"; classtype:trojan-activity; sid:100002055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.8.70.162"; classtype:trojan-activity; sid:100002056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.9.88.185"; classtype:trojan-activity; sid:100002057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.107.89.207"; classtype:trojan-activity; sid:100002058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.19.101.218"; classtype:trojan-activity; sid:100002059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.211.181.77"; classtype:trojan-activity; sid:100002060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.217.12.7"; classtype:trojan-activity; sid:100002061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.99.128.61"; classtype:trojan-activity; sid:100002062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.136.146.213"; classtype:trojan-activity; sid:100002063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.165.44.109"; classtype:trojan-activity; sid:100002064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.191.40.58"; classtype:trojan-activity; sid:100002065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.213.141.184"; classtype:trojan-activity; sid:100002066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.215.199.29"; classtype:trojan-activity; sid:100002067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.187.113"; classtype:trojan-activity; sid:100002068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.195.216"; classtype:trojan-activity; sid:100002069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.237.128.200"; classtype:trojan-activity; sid:100002070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.244.219.41"; classtype:trojan-activity; sid:100002071; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.246.225.203"; classtype:trojan-activity; sid:100002072; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.92.36.96"; classtype:trojan-activity; sid:100002073; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.103.108.72"; classtype:trojan-activity; sid:100002074; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.135.196.130"; classtype:trojan-activity; sid:100002075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.212.178"; classtype:trojan-activity; sid:100002076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.85.112"; classtype:trojan-activity; sid:100002077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.207.61.194"; classtype:trojan-activity; sid:100002078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.209.250.155"; classtype:trojan-activity; sid:100002079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.211.156.38"; classtype:trojan-activity; sid:100002080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.59.31.181"; classtype:trojan-activity; sid:100002081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.110.252"; classtype:trojan-activity; sid:100002082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.53.77"; classtype:trojan-activity; sid:100002083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.138.72"; classtype:trojan-activity; sid:100002084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.139.92"; classtype:trojan-activity; sid:100002085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.154.214"; classtype:trojan-activity; sid:100002086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.187.109"; classtype:trojan-activity; sid:100002087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.100.54"; classtype:trojan-activity; sid:100002088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.106.65"; classtype:trojan-activity; sid:100002089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.108.172"; classtype:trojan-activity; sid:100002090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.131.158"; classtype:trojan-activity; sid:100002091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.19.42"; classtype:trojan-activity; sid:100002092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.197.254"; classtype:trojan-activity; sid:100002093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.215.149"; classtype:trojan-activity; sid:100002094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.232.68"; classtype:trojan-activity; sid:100002095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.234.195"; classtype:trojan-activity; sid:100002096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.246.96"; classtype:trojan-activity; sid:100002097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.28.57"; classtype:trojan-activity; sid:100002098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.4.57"; classtype:trojan-activity; sid:100002099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.55.84"; classtype:trojan-activity; sid:100002100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.73.245"; classtype:trojan-activity; sid:100002101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.98.51"; classtype:trojan-activity; sid:100002102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.165.237.163"; classtype:trojan-activity; sid:100002103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.147.99"; classtype:trojan-activity; sid:100002104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.218.42"; classtype:trojan-activity; sid:100002105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.242.253.154"; classtype:trojan-activity; sid:100002106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.252.9.37"; classtype:trojan-activity; sid:100002107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.210.219.213"; classtype:trojan-activity; sid:100002108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.212.219.127"; classtype:trojan-activity; sid:100002109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.50.118"; classtype:trojan-activity; sid:100002110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.95.204"; classtype:trojan-activity; sid:100002111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.238.24.35"; classtype:trojan-activity; sid:100002112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.247.83.74"; classtype:trojan-activity; sid:100002113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.254.39.129"; classtype:trojan-activity; sid:100002114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.33.111.227"; classtype:trojan-activity; sid:100002115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.39.248.2"; classtype:trojan-activity; sid:100002116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.40.127.242"; classtype:trojan-activity; sid:100002117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.42.20.217"; classtype:trojan-activity; sid:100002118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; classtype:trojan-activity; sid:100002119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.11.216"; classtype:trojan-activity; sid:100002120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.123.251"; classtype:trojan-activity; sid:100002121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.135.187"; classtype:trojan-activity; sid:100002122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.180.33"; classtype:trojan-activity; sid:100002123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.224.141"; classtype:trojan-activity; sid:100002124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.241.2"; classtype:trojan-activity; sid:100002125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.214.149.236"; classtype:trojan-activity; sid:100002126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.64.181.50"; classtype:trojan-activity; sid:100002127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.64.203.204"; classtype:trojan-activity; sid:100002128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.74.215.180"; classtype:trojan-activity; sid:100002129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.130.227"; classtype:trojan-activity; sid:100002130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.195.129"; classtype:trojan-activity; sid:100002131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"86.35.43.220"; classtype:trojan-activity; sid:100002132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.172.19.130"; classtype:trojan-activity; sid:100002133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.61.89.40"; classtype:trojan-activity; sid:100002134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.119.171.253"; classtype:trojan-activity; sid:100002135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.208.71"; classtype:trojan-activity; sid:100002136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.219.179"; classtype:trojan-activity; sid:100002137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.225.222.128"; classtype:trojan-activity; sid:100002138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.247.96.19"; classtype:trojan-activity; sid:100002139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.136.231"; classtype:trojan-activity; sid:100002140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.51.139"; classtype:trojan-activity; sid:100002141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.249.244.180"; classtype:trojan-activity; sid:100002142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.204.12"; classtype:trojan-activity; sid:100002143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.226.26"; classtype:trojan-activity; sid:100002144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.240.245"; classtype:trojan-activity; sid:100002145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.254.90"; classtype:trojan-activity; sid:100002146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.122.183.130"; classtype:trojan-activity; sid:100002147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.136.197.170"; classtype:trojan-activity; sid:100002148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.22.152.244"; classtype:trojan-activity; sid:100002149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.29.213.33"; classtype:trojan-activity; sid:100002150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.85.166"; classtype:trojan-activity; sid:100002151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8poieq.bn.files.1drv.com"; classtype:trojan-activity; sid:100002152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"90.152.144.139"; classtype:trojan-activity; sid:100002153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.132.197.39"; classtype:trojan-activity; sid:100002154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.138.215.5"; classtype:trojan-activity; sid:100002155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.177.139.132"; classtype:trojan-activity; sid:100002156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.187.103.32"; classtype:trojan-activity; sid:100002157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.205.173.252"; classtype:trojan-activity; sid:100002158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.212.150.241"; classtype:trojan-activity; sid:100002159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.214.124.141"; classtype:trojan-activity; sid:100002160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.217.104.185"; classtype:trojan-activity; sid:100002161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.233.112.188"; classtype:trojan-activity; sid:100002162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.239.168.83"; classtype:trojan-activity; sid:100002163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.92.16.244"; classtype:trojan-activity; sid:100002164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.98.4.181"; classtype:trojan-activity; sid:100002165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.114.191.82"; classtype:trojan-activity; sid:100002166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.241.78.114"; classtype:trojan-activity; sid:100002167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.27.246.202"; classtype:trojan-activity; sid:100002168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.54.237.237"; classtype:trojan-activity; sid:100002169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.83.62.139"; classtype:trojan-activity; sid:100002170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.85.18.138"; classtype:trojan-activity; sid:100002171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.159.169.190"; classtype:trojan-activity; sid:100002172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.21.224.154"; classtype:trojan-activity; sid:100002173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.39.115.176"; classtype:trojan-activity; sid:100002174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.39.79.41"; classtype:trojan-activity; sid:100002175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.137.16"; classtype:trojan-activity; sid:100002176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.182.249"; classtype:trojan-activity; sid:100002177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.206.56"; classtype:trojan-activity; sid:100002178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.57.43.233"; classtype:trojan-activity; sid:100002179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.73.99.102"; classtype:trojan-activity; sid:100002180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.136.69.199"; classtype:trojan-activity; sid:100002181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.143.53.34"; classtype:trojan-activity; sid:100002182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.154.17.170"; classtype:trojan-activity; sid:100002183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.200.16.22"; classtype:trojan-activity; sid:100002184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.224.83.208"; classtype:trojan-activity; sid:100002185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.53.120.109"; classtype:trojan-activity; sid:100002186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.85.0.3"; classtype:trojan-activity; sid:100002187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.132.129.250"; classtype:trojan-activity; sid:100002188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.154.20.231"; classtype:trojan-activity; sid:100002189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.158.19.130"; classtype:trojan-activity; sid:100002190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.113.227"; classtype:trojan-activity; sid:100002191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.113.52"; classtype:trojan-activity; sid:100002192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.201.34"; classtype:trojan-activity; sid:100002193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.60.146.134"; classtype:trojan-activity; sid:100002194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.66.196.63"; classtype:trojan-activity; sid:100002195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.9.120.40"; classtype:trojan-activity; sid:100002196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.239.73.246"; classtype:trojan-activity; sid:100002197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.47.147.169"; classtype:trojan-activity; sid:100002198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.68.140.254"; classtype:trojan-activity; sid:100002199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.96.199.75"; classtype:trojan-activity; sid:100002200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.0.210.218"; classtype:trojan-activity; sid:100002201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.113.239.207"; classtype:trojan-activity; sid:100002202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.116.72.119"; classtype:trojan-activity; sid:100002203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.128.147.115"; classtype:trojan-activity; sid:100002204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.178.242.44"; classtype:trojan-activity; sid:100002205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.30.24.54"; classtype:trojan-activity; sid:100002206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.150.245.203"; classtype:trojan-activity; sid:100002207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.33.195.164"; classtype:trojan-activity; sid:100002208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aatreefelling.co.za"; classtype:trojan-activity; sid:100002209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abad.tv"; classtype:trojan-activity; sid:100002210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abcd.bg"; classtype:trojan-activity; sid:100002211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abissnet.net"; classtype:trojan-activity; sid:100002212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aboveandbelow.com.au"; classtype:trojan-activity; sid:100002213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absoftechworld.com"; classtype:trojan-activity; sid:100002214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absupplies.co.uk"; classtype:trojan-activity; sid:100002215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abyssos.eu"; classtype:trojan-activity; sid:100002216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"academyshademani.com"; classtype:trojan-activity; sid:100002217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acbick.com"; classtype:trojan-activity; sid:100002218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"accesslinksgroup.com"; classtype:trojan-activity; sid:100002219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aceeprc.com.aceeprc.com"; classtype:trojan-activity; sid:100002220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acellr.co.uk"; classtype:trojan-activity; sid:100002221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acteon.com.ar"; classtype:trojan-activity; sid:100002222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"activecost.com.au"; classtype:trojan-activity; sid:100002223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"addahealingmusic.com"; classtype:trojan-activity; sid:100002224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.com"; classtype:trojan-activity; sid:100002225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.memengers.com"; classtype:trojan-activity; sid:100002226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.erapor.smk-alasror.net"; classtype:trojan-activity; sid:100002227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.gentbcn.org"; classtype:trojan-activity; sid:100002228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.grandoceanvilla.com"; classtype:trojan-activity; sid:100002229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admission.kmctartskuttippuram.org"; classtype:trojan-activity; sid:100002230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adventureexplorer.in"; classtype:trojan-activity; sid:100002231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aeropilates.cl"; classtype:trojan-activity; sid:100002232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afnan-amc.com"; classtype:trojan-activity; sid:100002233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afoninblog.com"; classtype:trojan-activity; sid:100002234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afrimedspecialist.com"; classtype:trojan-activity; sid:100002235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agemn.co.za"; classtype:trojan-activity; sid:100002236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenciadigitalwdys.com"; classtype:trojan-activity; sid:100002237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenda.gmelloinformatica.com.br"; classtype:trojan-activity; sid:100002238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agentt.ac.ug"; classtype:trojan-activity; sid:100002239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agile8studio.com"; classtype:trojan-activity; sid:100002240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aiecons.com"; classtype:trojan-activity; sid:100002241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aimnaukri.com"; classtype:trojan-activity; sid:100002242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aiqtest.com"; classtype:trojan-activity; sid:100002243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aitorocio.com"; classtype:trojan-activity; sid:100002244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajpharmaholding.com"; classtype:trojan-activity; sid:100002245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajstudiollc.com"; classtype:trojan-activity; sid:100002246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"akdvidyalaya.com"; classtype:trojan-activity; sid:100002247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"al-wahd.com"; classtype:trojan-activity; sid:100002248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alasdemariposas.org"; classtype:trojan-activity; sid:100002249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alberts.diamondrelationscrm.us"; classtype:trojan-activity; sid:100002250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alemelektronik.com"; classtype:trojan-activity; sid:100002251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alena1971.es"; classtype:trojan-activity; sid:100002252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alexdubai.com.aldiabsteel.com"; classtype:trojan-activity; sid:100002253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alka.institute"; classtype:trojan-activity; sid:100002254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"allforcreative.com.au"; classtype:trojan-activity; sid:100002255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alltheway.travel"; classtype:trojan-activity; sid:100002256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alpaylar.com.tr"; classtype:trojan-activity; sid:100002257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"am-concepts.ca"; classtype:trojan-activity; sid:100002258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amamontajes.com"; classtype:trojan-activity; sid:100002259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarresdeamorymaestroshechiceros.com"; classtype:trojan-activity; sid:100002260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarteargentina.com.ar"; classtype:trojan-activity; sid:100002261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amos524.org"; classtype:trojan-activity; sid:100002262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ams.alvinasschools.org.ng"; classtype:trojan-activity; sid:100002263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anadelgbt.org"; classtype:trojan-activity; sid:100002264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anantam.net.in"; classtype:trojan-activity; sid:100002265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreelapeyre.com"; classtype:trojan-activity; sid:100002266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andremaraisbeleggings.co.za"; classtype:trojan-activity; sid:100002267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreonemaia.com"; classtype:trojan-activity; sid:100002268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ac.ug"; classtype:trojan-activity; sid:100002269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ug"; classtype:trojan-activity; sid:100002270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreshconcejal.solucioneslink.com"; classtype:trojan-activity; sid:100002271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelazgheibld.com"; classtype:trojan-activity; sid:100002272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelsdetour.com"; classtype:trojan-activity; sid:100002273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angloteste.bigprime.com.br"; classtype:trojan-activity; sid:100002274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anhung1102.vn"; classtype:trojan-activity; sid:100002275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anurontv.com"; classtype:trojan-activity; sid:100002276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anysbergbiltong.co.za"; classtype:trojan-activity; sid:100002277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api-ms.cobainaja.id"; classtype:trojan-activity; sid:100002278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.cstdevs.com"; classtype:trojan-activity; sid:100002279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.quocbao.biz"; classtype:trojan-activity; sid:100002280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apoolcondo.com"; classtype:trojan-activity; sid:100002281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.adsensearticle.com"; classtype:trojan-activity; sid:100002282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.explicitsurveys.co.uk"; classtype:trojan-activity; sid:100002283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.prerana.info"; classtype:trojan-activity; sid:100002284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apps.saintsoporte.com"; classtype:trojan-activity; sid:100002285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aps-scribe.com"; classtype:trojan-activity; sid:100002286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aps-sv.com"; classtype:trojan-activity; sid:100002287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apsusa.aero"; classtype:trojan-activity; sid:100002288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"areyoulivingwell.com"; classtype:trojan-activity; sid:100002289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"artedibujoyarquitectura.com"; classtype:trojan-activity; sid:100002290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"arwenyapi.com"; classtype:trojan-activity; sid:100002291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ask-regard.call-save.biz"; classtype:trojan-activity; sid:100002292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atfile.com"; classtype:trojan-activity; sid:100002293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"athenacapsg.com"; classtype:trojan-activity; sid:100002294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atlanticsteelprocessing.com"; classtype:trojan-activity; sid:100002295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atlasconcreteworks.com"; classtype:trojan-activity; sid:100002296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"attach.66rpg.com"; classtype:trojan-activity; sid:100002297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atteuqpotentialunlimited.com"; classtype:trojan-activity; sid:100002298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"augustair.com"; classtype:trojan-activity; sid:100002299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aulist.com"; classtype:trojan-activity; sid:100002300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"automaticrefreshments.com"; classtype:trojan-activity; sid:100002301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"avadhanagames.com"; classtype:trojan-activity; sid:100002302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ayahuascasp.com.br"; classtype:trojan-activity; sid:100002303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ayamallah.com"; classtype:trojan-activity; sid:100002304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aycconsultoriaempresarial.com"; classtype:trojan-activity; sid:100002305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azmeasurement.com"; classtype:trojan-activity; sid:100002306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"b2b.toptanakaryakit.com.tr"; classtype:trojan-activity; sid:100002307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"backgrounds.pk"; classtype:trojan-activity; sid:100002308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"badeggdesign.com"; classtype:trojan-activity; sid:100002309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"balealgodon.mx"; classtype:trojan-activity; sid:100002310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bangkok-orchids.com"; classtype:trojan-activity; sid:100002311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bangladeshunbound.com"; classtype:trojan-activity; sid:100002312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bary.sz4h.com"; classtype:trojan-activity; sid:100002313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bash.givemexyz.in"; classtype:trojan-activity; sid:100002314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; classtype:trojan-activity; sid:100002315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bavhome.com"; classtype:trojan-activity; sid:100002316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bbia.co.uk"; classtype:trojan-activity; sid:100002317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcmt.elin.co.za"; classtype:trojan-activity; sid:100002318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcrg.co.za"; classtype:trojan-activity; sid:100002319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bdnextrend.xyz"; classtype:trojan-activity; sid:100002320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beanx88.xyz"; classtype:trojan-activity; sid:100002321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bearcatpumps.com.cn"; classtype:trojan-activity; sid:100002322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beautincollagen.rs"; classtype:trojan-activity; sid:100002323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bekape.co.id"; classtype:trojan-activity; sid:100002324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beor360.com"; classtype:trojan-activity; sid:100002325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bespokeweddings.ie"; classtype:trojan-activity; sid:100002326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bestcarenepal.com"; classtype:trojan-activity; sid:100002327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betone.co.kr"; classtype:trojan-activity; sid:100002328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betycopaints.com"; classtype:trojan-activity; sid:100002329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beveragesmiami.solucioneslink.com"; classtype:trojan-activity; sid:100002330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bhavaniengineering.com"; classtype:trojan-activity; sid:100002331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bigmikesupplies.co.za"; classtype:trojan-activity; sid:100002332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilbosaquet.ug"; classtype:trojan-activity; sid:100002333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilhen.co.za"; classtype:trojan-activity; sid:100002334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"billing.citywine.in"; classtype:trojan-activity; sid:100002335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"billing.rahitechnosoft.com"; classtype:trojan-activity; sid:100002336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"binoy.stalphonsamissionva.org"; classtype:trojan-activity; sid:100002337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"biometrico.gpotecnosystems.com"; classtype:trojan-activity; sid:100002338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bioskey.com"; classtype:trojan-activity; sid:100002339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birdi.elin.co.za"; classtype:trojan-activity; sid:100002340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birminghamlink.org"; classtype:trojan-activity; sid:100002341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bizztradingbot.nl"; classtype:trojan-activity; sid:100002342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bl4n3.zadns.co.za"; classtype:trojan-activity; sid:100002343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.callensaxen.com"; classtype:trojan-activity; sid:100002344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.cast.re"; classtype:trojan-activity; sid:100002345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.difusodesign.com"; classtype:trojan-activity; sid:100002346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.oyinblogs.com"; classtype:trojan-activity; sid:100002347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.takbelit.com"; classtype:trojan-activity; sid:100002348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bmlifestyle.co.uk"; classtype:trojan-activity; sid:100002349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bnrnews.id"; classtype:trojan-activity; sid:100002350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"boatpecas.com.br"; classtype:trojan-activity; sid:100002351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bodenstein.co.za"; classtype:trojan-activity; sid:100002352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"booksearch.com"; classtype:trojan-activity; sid:100002353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bophelocare.co.za"; classtype:trojan-activity; sid:100002354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bounces.mi-fs.com"; classtype:trojan-activity; sid:100002355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"boutiqueofferte.com"; classtype:trojan-activity; sid:100002356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bpo.correct.go.th"; classtype:trojan-activity; sid:100002357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bradleyinstitute.co.za"; classtype:trojan-activity; sid:100002358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brandtrust.com.pk"; classtype:trojan-activity; sid:100002359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"braunfinancial.com.au"; classtype:trojan-activity; sid:100002360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brendanquine.com"; classtype:trojan-activity; sid:100002361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brideofmessiah.com"; classtype:trojan-activity; sid:100002362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightaffiliatesales.org"; classtype:trojan-activity; sid:100002363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightmega.com"; classtype:trojan-activity; sid:100002364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightstarshop.com"; classtype:trojan-activity; sid:100002365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"browardinsurancemiami.solucioneslink.com"; classtype:trojan-activity; sid:100002366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bt2.elin.co.za"; classtype:trojan-activity; sid:100002367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"btdapi.robotake.com"; classtype:trojan-activity; sid:100002368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buigiaphat.com.vn"; classtype:trojan-activity; sid:100002369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bulkyfoodja.com"; classtype:trojan-activity; sid:100002370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bullseyemedia.in"; classtype:trojan-activity; sid:100002371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"busandvanrentalmalaysia.com"; classtype:trojan-activity; sid:100002372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buscascolegios.diit.cl"; classtype:trojan-activity; sid:100002373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"business.softberg.ro"; classtype:trojan-activity; sid:100002374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"business2.softberg.ro"; classtype:trojan-activity; sid:100002375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bydspa.cl"; classtype:trojan-activity; sid:100002376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c.oooooooooo.ga"; classtype:trojan-activity; sid:100002377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c0140529.ferozo.com"; classtype:trojan-activity; sid:100002378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"caballo.com.au"; classtype:trojan-activity; sid:100002379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cacaoprojects.com"; classtype:trojan-activity; sid:100002380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"calgaryautorepairservice.com"; classtype:trojan-activity; sid:100002381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"callbury.in"; classtype:trojan-activity; sid:100002382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"camminachetipassa.it"; classtype:trojan-activity; sid:100002383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"canadianwork.cc"; classtype:trojan-activity; sid:100002384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capitalgroup-kw.com"; classtype:trojan-activity; sid:100002385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capoeiraventrelivre.com"; classtype:trojan-activity; sid:100002386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cardilicores.com"; classtype:trojan-activity; sid:100002387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cashyinvestment.org"; classtype:trojan-activity; sid:100002388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"catchperch.com"; classtype:trojan-activity; sid:100002389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"catchpoolshetlands.co.uk"; classtype:trojan-activity; sid:100002390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cazyacustomfurniture.com"; classtype:trojan-activity; sid:100002391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cbn.hypervoizd.com"; classtype:trojan-activity; sid:100002392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ccauthority.net"; classtype:trojan-activity; sid:100002393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cdaonline.com.ar"; classtype:trojan-activity; sid:100002394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cec.asso.ac-amiens.fr"; classtype:trojan-activity; sid:100002395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cecra.cl"; classtype:trojan-activity; sid:100002396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cellas.sk"; classtype:trojan-activity; sid:100002397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cendekiabinaaksara.com"; classtype:trojan-activity; sid:100002398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cfs5.tistory.com"; classtype:trojan-activity; sid:100002399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ch.rmu.ac.th"; classtype:trojan-activity; sid:100002400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chance5.xyz"; classtype:trojan-activity; sid:100002401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"changematterscounselling.com"; classtype:trojan-activity; sid:100002402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chardhamdodham.com"; classtype:trojan-activity; sid:100002403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"check.askwordpressguru.com"; classtype:trojan-activity; sid:100002404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chezalice.co.za"; classtype:trojan-activity; sid:100002405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"childselect.com"; classtype:trojan-activity; sid:100002406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile.myvnc.com"; classtype:trojan-activity; sid:100002407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile80.myvnc.com"; classtype:trojan-activity; sid:100002408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chipmania.it"; classtype:trojan-activity; sid:100002409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cible-energy.com"; classtype:trojan-activity; sid:100002410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cifeer.net"; classtype:trojan-activity; sid:100002411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cirugiadenarizbucaramanga.com"; classtype:trojan-activity; sid:100002412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citihits.lk"; classtype:trojan-activity; sid:100002413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citssolutions.co.za"; classtype:trojan-activity; sid:100002414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citycapproperty.ru"; classtype:trojan-activity; sid:100002415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cityglobalgospel.com"; classtype:trojan-activity; sid:100002416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"civi.istmejia.com"; classtype:trojan-activity; sid:100002417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cleanbydesignllc.com"; classtype:trojan-activity; sid:100002418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cloud.fc.co.mz"; classtype:trojan-activity; sid:100002419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cm-arquitetos.com"; classtype:trojan-activity; sid:100002420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"codsambal.com"; classtype:trojan-activity; sid:100002421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colempaques.info"; classtype:trojan-activity; sid:100002422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colorpak.pl"; classtype:trojan-activity; sid:100002423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"columbia.aula-web.net"; classtype:trojan-activity; sid:100002424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"community.reimclub.com"; classtype:trojan-activity; sid:100002425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"competancy.indigoconsult.net"; classtype:trojan-activity; sid:100002426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"conceptimagine.ro"; classtype:trojan-activity; sid:100002427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"config.cqhbkjzx.com"; classtype:trojan-activity; sid:100002428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"connectcapital.com.br"; classtype:trojan-activity; sid:100002429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"constructoralyon.com"; classtype:trojan-activity; sid:100002430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"consulateins.solucioneslink.com"; classtype:trojan-activity; sid:100002431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"contributeindustry.com"; classtype:trojan-activity; sid:100002432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"controleautomacao.com.br"; classtype:trojan-activity; sid:100002433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"copelandscapes.com"; classtype:trojan-activity; sid:100002434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"coulsongraphics.com"; classtype:trojan-activity; sid:100002435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"count.mail.163.com.impactmedfoundation.com"; classtype:trojan-activity; sid:100002436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"covid19.cyberschool.or.id"; classtype:trojan-activity; sid:100002437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cpanel.shivay.net"; classtype:trojan-activity; sid:100002438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cr-sq.com"; classtype:trojan-activity; sid:100002439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"craftech.nxtnet.ga"; classtype:trojan-activity; sid:100002440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"creationskateboards.com"; classtype:trojan-activity; sid:100002441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crecerco.com"; classtype:trojan-activity; sid:100002442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crittersbythebay.com"; classtype:trojan-activity; sid:100002443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crm.notariavieitoyvelamazan.com"; classtype:trojan-activity; sid:100002444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crmfarko.manivelasst.com"; classtype:trojan-activity; sid:100002445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crmroche.manivelasst.com"; classtype:trojan-activity; sid:100002446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crscorretordeimoveis.com.br"; classtype:trojan-activity; sid:100002447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cse-engineer.com"; classtype:trojan-activity; sid:100002448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"csnserver.com"; classtype:trojan-activity; sid:100002449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cubescargoexpress.com"; classtype:trojan-activity; sid:100002450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"curasoles.co.za"; classtype:trojan-activity; sid:100002451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"currantmedia.com"; classtype:trojan-activity; sid:100002452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cwa.mx"; classtype:trojan-activity; sid:100002453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cyclomove.com"; classtype:trojan-activity; sid:100002454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cynkon.kairoscs.net"; classtype:trojan-activity; sid:100002455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"czsl.91756.cn"; classtype:trojan-activity; sid:100002456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d.powerofwish.com"; classtype:trojan-activity; sid:100002457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d9.99ddd.com"; classtype:trojan-activity; sid:100002458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"da.alibuf.com"; classtype:trojan-activity; sid:100002459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dagiionline.com"; classtype:trojan-activity; sid:100002460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"damagedessentialtelecommunications.testmail4.repl.co"; classtype:trojan-activity; sid:100002461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"danaevara.com"; classtype:trojan-activity; sid:100002462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dartoonpictures.com"; classtype:trojan-activity; sid:100002463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.cdevelop.org"; classtype:trojan-activity; sid:100002464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.over-blog-kiwi.com"; classtype:trojan-activity; sid:100002465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datapolish.com"; classtype:trojan-activity; sid:100002466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dating.khokhas.co.za"; classtype:trojan-activity; sid:100002467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davethompson.me.uk"; classtype:trojan-activity; sid:100002468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davidmcguinness.info"; classtype:trojan-activity; sid:100002469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dayspringdaisies.com"; classtype:trojan-activity; sid:100002470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dd.qiyuea.cn"; classtype:trojan-activity; sid:100002471; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"de.gsearch.com.de"; classtype:trojan-activity; sid:100002472; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"decifrar.com.br"; classtype:trojan-activity; sid:100002473; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"deigratia2.elin.co.za"; classtype:trojan-activity; sid:100002474; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dekovizyon.com"; classtype:trojan-activity; sid:100002475; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo-cliente.mindcreative.com.br"; classtype:trojan-activity; sid:100002476; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo.glassforcars.com.au"; classtype:trojan-activity; sid:100002477; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo.iiitindia.in"; classtype:trojan-activity; sid:100002478; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo6.hiites.com"; classtype:trojan-activity; sid:100002479; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dent-estet.com"; classtype:trojan-activity; sid:100002480; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dental.xiaoxiao.media"; classtype:trojan-activity; sid:100002481; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dentalalliance.se"; classtype:trojan-activity; sid:100002482; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"desertlandtrd.com"; classtype:trojan-activity; sid:100002483; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"designerliving.co.za"; classtype:trojan-activity; sid:100002484; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"desiringhands.com"; classtype:trojan-activity; sid:100002485; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"despertaresi.com.br"; classtype:trojan-activity; sid:100002486; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"destinymc.co.za"; classtype:trojan-activity; sid:100002487; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"detorre.es"; classtype:trojan-activity; sid:100002488; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev.sebpo.net"; classtype:trojan-activity; sid:100002489; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev.watch-store.eu"; classtype:trojan-activity; sid:100002490; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dfcf.91756.cn"; classtype:trojan-activity; sid:100002491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dfsfcsfcdsfsdvcfsvcscv.com"; classtype:trojan-activity; sid:100002492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"diamantenegro.mi-fs.com"; classtype:trojan-activity; sid:100002493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dienmayminhhung.com"; classtype:trojan-activity; sid:100002494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"digilib.dianhusada.ac.id"; classtype:trojan-activity; sid:100002495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"digisails.org"; classtype:trojan-activity; sid:100002496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"disinfection-cleaning.co.za"; classtype:trojan-activity; sid:100002497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"djking.f3322.net"; classtype:trojan-activity; sid:100002498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.1003b.56a.com"; classtype:trojan-activity; sid:100002499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.198424.com"; classtype:trojan-activity; sid:100002500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.installcdn-aws.com"; classtype:trojan-activity; sid:100002501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.packetstormsecurity.net"; classtype:trojan-activity; sid:100002502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.rina-roleplay.com"; classtype:trojan-activity; sid:100002503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dnn.alibuf.com"; classtype:trojan-activity; sid:100002504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dns.alibuf.com"; classtype:trojan-activity; sid:100002505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dns.cyberium.cc"; classtype:trojan-activity; sid:100002506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dockerupdate.anondns.net"; classtype:trojan-activity; sid:100002507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"docman.orientalservices.in"; classtype:trojan-activity; sid:100002508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dodsonimaging.com"; classtype:trojan-activity; sid:100002509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"doitunlimited.com"; classtype:trojan-activity; sid:100002510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dokan.blueberrytec.com"; classtype:trojan-activity; sid:100002511; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom-chel74.ru"; classtype:trojan-activity; sid:100002512; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom.daf.free.fr"; classtype:trojan-activity; sid:100002513; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"doncedyhall.com"; classtype:trojan-activity; sid:100002514; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"donghobinhminh.com"; classtype:trojan-activity; sid:100002515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dongphuctop.com"; classtype:trojan-activity; sid:100002516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"donwnloasecury.ath.cx"; classtype:trojan-activity; sid:100002517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosame.com"; classtype:trojan-activity; sid:100002518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosman.pl"; classtype:trojan-activity; sid:100002519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dovberger.com"; classtype:trojan-activity; sid:100002520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.pcclear.com"; classtype:trojan-activity; sid:100002521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.postch-de.top"; classtype:trojan-activity; sid:100002522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.postch-dl.top"; classtype:trojan-activity; sid:100002523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.udashi.com"; classtype:trojan-activity; sid:100002524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.webbora.com"; classtype:trojan-activity; sid:100002525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down1.arpun.com"; classtype:trojan-activity; sid:100002526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.caihong.com"; classtype:trojan-activity; sid:100002527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.doumaibiji.cn"; classtype:trojan-activity; sid:100002528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.exrnybuf.cn"; classtype:trojan-activity; sid:100002529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.kaobeitu.com"; classtype:trojan-activity; sid:100002530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.pdf00.cn"; classtype:trojan-activity; sid:100002531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.rising.com.cn"; classtype:trojan-activity; sid:100002532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.skycn.com"; classtype:trojan-activity; sid:100002533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.zjsyawqj.cn"; classtype:trojan-activity; sid:100002534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dragonsknot.com"; classtype:trojan-activity; sid:100002535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drbaby.com.sa"; classtype:trojan-activity; sid:100002536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dream.pics"; classtype:trojan-activity; sid:100002537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drgroup.co.za"; classtype:trojan-activity; sid:100002538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drools-moved.46999.n3.nabble.com"; classtype:trojan-activity; sid:100002539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drsha.innovativesolutions.mobi"; classtype:trojan-activity; sid:100002540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsdisplay.co.uk"; classtype:trojan-activity; sid:100002541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsenterprize.co.za"; classtype:trojan-activity; sid:100002542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsspainting.com"; classtype:trojan-activity; sid:100002543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"du-wizards.com"; classtype:trojan-activity; sid:100002544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duanhaozhang.com"; classtype:trojan-activity; sid:100002545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duque.guantanameratravel.com"; classtype:trojan-activity; sid:100002546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dutapp.wisolve.co.za"; classtype:trojan-activity; sid:100002547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duvalcharter.dekitout.com"; classtype:trojan-activity; sid:100002548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dx.qqyewu.com"; classtype:trojan-activity; sid:100002549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dzinestudio87.co.uk"; classtype:trojan-activity; sid:100002550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e-commerce.saleensuporte.com.br"; classtype:trojan-activity; sid:100002551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e.sldov.ru"; classtype:trojan-activity; sid:100002552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eandgdesign.com.ng"; classtype:trojan-activity; sid:100002553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eastsheen-glaziers.co.uk"; classtype:trojan-activity; sid:100002554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ebruyatkin.com"; classtype:trojan-activity; sid:100002555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"edu.saicraftsman.com"; classtype:trojan-activity; sid:100002556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eedo.ee"; classtype:trojan-activity; sid:100002557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"efficientegroup.com"; classtype:trojan-activity; sid:100002558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"elbauldenora.com"; classtype:trojan-activity; sid:100002559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"emaids.co.za"; classtype:trojan-activity; sid:100002560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"emaz.pk"; classtype:trojan-activity; sid:100002561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"emlak.ygtsoft.com"; classtype:trojan-activity; sid:100002562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"en.baoend.com"; classtype:trojan-activity; sid:100002563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enc-tech.com"; classtype:trojan-activity; sid:100002564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"endurotanzania.co.tz"; classtype:trojan-activity; sid:100002565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ennovate.elin.co.za"; classtype:trojan-activity; sid:100002566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enriquecendocomconsorcio.com.br"; classtype:trojan-activity; sid:100002567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"equimination.ee"; classtype:trojan-activity; sid:100002568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"erp.nanotechproautocare.com"; classtype:trojan-activity; sid:100002569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"erp.zilymax.com"; classtype:trojan-activity; sid:100002570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"escola.probommar.org.br"; classtype:trojan-activity; sid:100002571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"esnconsultants.com"; classtype:trojan-activity; sid:100002572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"essentia.org.br"; classtype:trojan-activity; sid:100002573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eubanks7.com"; classtype:trojan-activity; sid:100002574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"europeanzonexxi.com"; classtype:trojan-activity; sid:100002575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"evidencemarketing.ca"; classtype:trojan-activity; sid:100002576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exilum.com"; classtype:trojan-activity; sid:100002577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exitoalfaomega.co"; classtype:trojan-activity; sid:100002578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"extrovertoffers.com"; classtype:trojan-activity; sid:100002579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"f1sol.com"; classtype:trojan-activity; sid:100002580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fahrzeugdrive.com"; classtype:trojan-activity; sid:100002581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"familydentist.site"; classtype:trojan-activity; sid:100002582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fc.co.mz"; classtype:trojan-activity; sid:100002583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"felicienne.nl"; classtype:trojan-activity; sid:100002584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"files.martellexpress.us"; classtype:trojan-activity; sid:100002585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"filmotainment.com"; classtype:trojan-activity; sid:100002586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"final.makkahkmcc.com"; classtype:trojan-activity; sid:100002587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fineartgallerym.com"; classtype:trojan-activity; sid:100002588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fisconline.bar"; classtype:trojan-activity; sid:100002589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fix-america-now.org"; classtype:trojan-activity; sid:100002590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fixauto.illumetechnology.com"; classtype:trojan-activity; sid:100002591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fixturegovernment.com"; classtype:trojan-activity; sid:100002592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fkd.derpcity.ru"; classtype:trojan-activity; sid:100002593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flexypay.dsquaregroup.com"; classtype:trojan-activity; sid:100002594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flintspin.com"; classtype:trojan-activity; sid:100002595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flyingbuddhadesign.com"; classtype:trojan-activity; sid:100002596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fmjplastering.co.uk"; classtype:trojan-activity; sid:100002597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fms.buladde.or.ug"; classtype:trojan-activity; sid:100002598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"follower.instantcashback.in"; classtype:trojan-activity; sid:100002599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foothills.com.br"; classtype:trojan-activity; sid:100002600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"footweardirect.elin.co.za"; classtype:trojan-activity; sid:100002601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"forum.mdb.nu"; classtype:trojan-activity; sid:100002602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fotoobjetivo.com"; classtype:trojan-activity; sid:100002603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foxeps.com.br"; classtype:trojan-activity; sid:100002604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fraud.bpcbankingtech.com"; classtype:trojan-activity; sid:100002605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freecnetdownload.com"; classtype:trojan-activity; sid:100002606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freisites.com.br"; classtype:trojan-activity; sid:100002607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ftp.n3twork30cm.ml"; classtype:trojan-activity; sid:100002608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fullelectronica.com.ar"; classtype:trojan-activity; sid:100002609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"funletters.net"; classtype:trojan-activity; sid:100002610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fusionfiresolutions.com"; classtype:trojan-activity; sid:100002611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"futuregraphics.com.ar"; classtype:trojan-activity; sid:100002612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"g.pinmonkey.xyz"; classtype:trojan-activity; sid:100002613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gametwogame.com"; classtype:trojan-activity; sid:100002614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garciadogshow.com"; classtype:trojan-activity; sid:100002615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow.myvnc.com"; classtype:trojan-activity; sid:100002616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow4.myvnc.com"; classtype:trojan-activity; sid:100002617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gastoudergonny.nl"; classtype:trojan-activity; sid:100002618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gbbulls.co.uk"; classtype:trojan-activity; sid:100002619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gcpc.co.id.chronoscurtain.com"; classtype:trojan-activity; sid:100002620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"generaldeviales.com"; classtype:trojan-activity; sid:100002621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfmodd1.webselffiles01.com"; classtype:trojan-activity; sid:100002622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfold1.webselffiles01.com"; classtype:trojan-activity; sid:100002623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghettohub.co.za"; classtype:trojan-activity; sid:100002624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghislain.dartois.pagesperso-orange.fr"; classtype:trojan-activity; sid:100002625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giadungg7.com"; classtype:trojan-activity; sid:100002626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giddos.ga"; classtype:trojan-activity; sid:100002627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giteletropical.com"; classtype:trojan-activity; sid:100002628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"glowinmedia.co.ke"; classtype:trojan-activity; sid:100002629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmsebpl.com"; classtype:trojan-activity; sid:100002630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmtransformationacademy.com"; classtype:trojan-activity; sid:100002631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmvadmission.org"; classtype:trojan-activity; sid:100002632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnimelf.net"; classtype:trojan-activity; sid:100002633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnscrew.ro"; classtype:trojan-activity; sid:100002634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gold.investforex.id"; classtype:trojan-activity; sid:100002635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcake.co.id"; classtype:trojan-activity; sid:100002636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com"; classtype:trojan-activity; sid:100002637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com.au"; classtype:trojan-activity; sid:100002638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"golden-memories-funerals.yourpageserver.com"; classtype:trojan-activity; sid:100002639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldenasiacapital.com"; classtype:trojan-activity; sid:100002640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldmen.in"; classtype:trojan-activity; sid:100002641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gorecycle.fahadjutt.com"; classtype:trojan-activity; sid:100002642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gpotecnosystems.com"; classtype:trojan-activity; sid:100002643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gracejukes.com"; classtype:trojan-activity; sid:100002644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"grovershospital.com"; classtype:trojan-activity; sid:100002645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"grupoinmare.com"; classtype:trojan-activity; sid:100002646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gruposelt.000webhostapp.com"; classtype:trojan-activity; sid:100002647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gruppodomus.com.br"; classtype:trojan-activity; sid:100002648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gs.monerorx.com"; classtype:trojan-activity; sid:100002649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"guide-to-cell-phones.com"; classtype:trojan-activity; sid:100002650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gulfac-house.com"; classtype:trojan-activity; sid:100002651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gvpcdpgc.edu.in"; classtype:trojan-activity; sid:100002652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"habbotips.free.fr"; classtype:trojan-activity; sid:100002653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hagebakken.no"; classtype:trojan-activity; sid:100002654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hamptonpartyoffive.com"; classtype:trojan-activity; sid:100002655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hashmati.com"; classtype:trojan-activity; sid:100002656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hassanproduct.com"; classtype:trojan-activity; sid:100002657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hchfug.org"; classtype:trojan-activity; sid:100002658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hd11315.com"; classtype:trojan-activity; sid:100002659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hdkamera2003.hu"; classtype:trojan-activity; sid:100002660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hds.sz4h.com"; classtype:trojan-activity; sid:100002661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"heavymaq.cl"; classtype:trojan-activity; sid:100002662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hellogorgeous.com.au"; classtype:trojan-activity; sid:100002663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"help.hizuko.com"; classtype:trojan-activity; sid:100002664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"herchinfitout.com.sg"; classtype:trojan-activity; sid:100002665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hhaward.org"; classtype:trojan-activity; sid:100002666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandroadcoc.com"; classtype:trojan-activity; sid:100002667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandslasvegas.atakdev.com"; classtype:trojan-activity; sid:100002668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hindi.factsriver.com"; classtype:trojan-activity; sid:100002669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitpe.com"; classtype:trojan-activity; sid:100002670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitstation.nl"; classtype:trojan-activity; sid:100002671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hlmd.in"; classtype:trojan-activity; sid:100002672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hmpmall.co.kr"; classtype:trojan-activity; sid:100002673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoagietesting10.com"; classtype:trojan-activity; sid:100002674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoayeuthuong-my.sharepoint.com"; classtype:trojan-activity; sid:100002675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"homefindersolutions.com"; classtype:trojan-activity; sid:100002676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hongluosi.com"; classtype:trojan-activity; sid:100002677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hookedupboatclub.com"; classtype:trojan-activity; sid:100002678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hortizwp.eastus.cloudapp.azure.com"; classtype:trojan-activity; sid:100002679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostingparacolombia.com"; classtype:trojan-activity; sid:100002680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostzaa.com"; classtype:trojan-activity; sid:100002681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"houstonshutters.site"; classtype:trojan-activity; sid:100002682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hr2019.vrcom7.com"; classtype:trojan-activity; sid:100002683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hrnautica.com.br"; classtype:trojan-activity; sid:100002684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hseda.com"; classtype:trojan-activity; sid:100002685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"htownbars.com"; classtype:trojan-activity; sid:100002686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hubtech.co.za"; classtype:trojan-activity; sid:100002687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"huellacero.cl"; classtype:trojan-activity; sid:100002688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hunggiang.vn"; classtype:trojan-activity; sid:100002689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"husamiyahschool.com"; classtype:trojan-activity; sid:100002690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iabmixx2020.rayadigital.online"; classtype:trojan-activity; sid:100002691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iam313.com"; classtype:trojan-activity; sid:100002692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iammdshanto.com"; classtype:trojan-activity; sid:100002693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"icon.shatangmu.cn"; classtype:trojan-activity; sid:100002694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idilsoft.com"; classtype:trojan-activity; sid:100002695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idj.no"; classtype:trojan-activity; sid:100002696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idvindia.com"; classtype:trojan-activity; sid:100002697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ieclb.com.br"; classtype:trojan-activity; sid:100002698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ikexpert.com"; classtype:trojan-activity; sid:100002699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ilrafrica.com"; classtype:trojan-activity; sid:100002700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"images.jermiau.com"; classtype:trojan-activity; sid:100002701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"imbueautoworx.co.za"; classtype:trojan-activity; sid:100002702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"in-tune2016.com"; classtype:trojan-activity; sid:100002703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incrediblepixels.com"; classtype:trojan-activity; sid:100002704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incredicole.com"; classtype:trojan-activity; sid:100002705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"indrasbikaner.com"; classtype:trojan-activity; sid:100002706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infair.vn"; classtype:trojan-activity; sid:100002707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infovator.com"; classtype:trojan-activity; sid:100002708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"initialnetworks.com"; classtype:trojan-activity; sid:100002709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inodesthetotaldesigners.com"; classtype:trojan-activity; sid:100002710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inrajahmundry.co.in"; classtype:trojan-activity; sid:100002711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"insignificantfinecore.testmail4.repl.co"; classtype:trojan-activity; sid:100002712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"instantindialoan.com"; classtype:trojan-activity; sid:100002713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"insupportofchildren.co.uk"; classtype:trojan-activity; sid:100002714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intellectsmart.in"; classtype:trojan-activity; sid:100002715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intersel-idf.org"; classtype:trojan-activity; sid:100002716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intuitiveideas.com.my"; classtype:trojan-activity; sid:100002717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inversiones.arrayanfinanciero.cl"; classtype:trojan-activity; sid:100002718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"invest.xpcorporative.com.br"; classtype:trojan-activity; sid:100002719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"investinae.com"; classtype:trojan-activity; sid:100002720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ioabc.wif.com.br"; classtype:trojan-activity; sid:100002721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ipmes.ma"; classtype:trojan-activity; sid:100002722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iremart.es"; classtype:trojan-activity; sid:100002723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iris101.co.uk"; classtype:trojan-activity; sid:100002724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isaac.mikhailmotoringschool.com"; classtype:trojan-activity; sid:100002725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iscamenabe.com"; classtype:trojan-activity; sid:100002726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isiphephelocon.co.za"; classtype:trojan-activity; sid:100002727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iso-dubai.net"; classtype:trojan-activity; sid:100002728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"israrulhaq.me"; classtype:trojan-activity; sid:100002729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isrorg.com"; classtype:trojan-activity; sid:100002730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isso.ps"; classtype:trojan-activity; sid:100002731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ist-security.com"; classtype:trojan-activity; sid:100002732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"it123.ru"; classtype:trojan-activity; sid:100002733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"italiandirezione.casa"; classtype:trojan-activity; sid:100002734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itc-demo.softgig.co.ke"; classtype:trojan-activity; sid:100002735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itelsys.ma"; classtype:trojan-activity; sid:100002736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itmotasaciones.com"; classtype:trojan-activity; sid:100002737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jacktech.jackindia.com"; classtype:trojan-activity; sid:100002738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jaishritours.com"; classtype:trojan-activity; sid:100002739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamiekaylive.com"; classtype:trojan-activity; sid:100002740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamshed.pk"; classtype:trojan-activity; sid:100002741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jansen-heesch.nl"; classtype:trojan-activity; sid:100002742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jathra.co.uk"; classtype:trojan-activity; sid:100002743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jay.diamondrelationscrm.us"; classtype:trojan-activity; sid:100002744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jebs.net.au"; classtype:trojan-activity; sid:100002745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jeffdahlke.com"; classtype:trojan-activity; sid:100002746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jennwolfemtb.com"; classtype:trojan-activity; sid:100002747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jhayesconsulting.com"; classtype:trojan-activity; sid:100002748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jiaoyuzixun.cn"; classtype:trojan-activity; sid:100002749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jing-da.com.tw"; classtype:trojan-activity; sid:100002750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jmtc.91756.cn"; classtype:trojan-activity; sid:100002751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jnanbharati.com"; classtype:trojan-activity; sid:100002752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jobs.thebeessolution.com"; classtype:trojan-activity; sid:100002753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"joelbonissilver.com"; classtype:trojan-activity; sid:100002754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"join.cl8movement.co.za"; classtype:trojan-activity; sid:100002755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"josegene.com"; classtype:trojan-activity; sid:100002756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jpwoodfordco.com"; classtype:trojan-activity; sid:100002757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jumpmanualjacobhiller.com"; classtype:trojan-activity; sid:100002758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jupiter.toxsl.in"; classtype:trojan-activity; sid:100002759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"justinscott.com.au"; classtype:trojan-activity; sid:100002760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kadigital.co.uk"; classtype:trojan-activity; sid:100002761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kaizenjanitorial.com"; classtype:trojan-activity; sid:100002762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalawatihomes.com"; classtype:trojan-activity; sid:100002763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalogirosfinance.com"; classtype:trojan-activity; sid:100002764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kaptaanchapal.com"; classtype:trojan-activity; sid:100002765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"karer.by"; classtype:trojan-activity; sid:100002766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"katanvetov.co.il"; classtype:trojan-activity; sid:100002767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kensingtondriving.com"; classtype:trojan-activity; sid:100002768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ketofitnessexpert.com"; classtype:trojan-activity; sid:100002769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kevinjewelry.com.co"; classtype:trojan-activity; sid:100002770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"keywatch.yourpageserver.com"; classtype:trojan-activity; sid:100002771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kingssa.co.za"; classtype:trojan-activity; sid:100002772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kjcpromo.com"; classtype:trojan-activity; sid:100002773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kleinendeli.co.za"; classtype:trojan-activity; sid:100002774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"korrectconceptservices.com"; classtype:trojan-activity; sid:100002775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"krisbadminton.com"; classtype:trojan-activity; sid:100002776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ktb.sch.id"; classtype:trojan-activity; sid:100002777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kubatoglubaklava.com.tr"; classtype:trojan-activity; sid:100002778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kumaralok.in"; classtype:trojan-activity; sid:100002779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kwanfromhongkong.com"; classtype:trojan-activity; sid:100002780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kz.sldov.ru"; classtype:trojan-activity; sid:100002781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lacasadelosalebrijes.com"; classtype:trojan-activity; sid:100002782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ladylabonde.com"; classtype:trojan-activity; sid:100002783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lameguard.ru"; classtype:trojan-activity; sid:100002784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laodongnhat.vn"; classtype:trojan-activity; sid:100002785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laravel.pointersoftwares.com.br"; classtype:trojan-activity; sid:100002786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lasermobilesounds.co.uk"; classtype:trojan-activity; sid:100002787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laura9630fr.com"; classtype:trojan-activity; sid:100002788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lauratomismith.com"; classtype:trojan-activity; sid:100002789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lautarosanmiguel.com"; classtype:trojan-activity; sid:100002790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lawforall.edu.lk"; classtype:trojan-activity; sid:100002791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lawschoolideas.xyz"; classtype:trojan-activity; sid:100002792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lceventos.net"; classtype:trojan-activity; sid:100002793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ld.mediaget.com"; classtype:trojan-activity; sid:100002794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ldgcorp.com"; classtype:trojan-activity; sid:100002795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"learning.real-academy.net"; classtype:trojan-activity; sid:100002796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leasiacherise.com"; classtype:trojan-activity; sid:100002797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leczkregoslup.acelero.pl"; classtype:trojan-activity; sid:100002798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"legend.nu"; classtype:trojan-activity; sid:100002799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leluibuffet.com.br"; classtype:trojan-activity; sid:100002800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lestesteux.ca"; classtype:trojan-activity; sid:100002801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"libantravel.pl"; classtype:trojan-activity; sid:100002802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.arihantmbainstitute.ac.in"; classtype:trojan-activity; sid:100002803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.uib.ac.id"; classtype:trojan-activity; sid:100002804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lidoraggiodisole.it"; classtype:trojan-activity; sid:100002805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lifebeam.elin.co.za"; classtype:trojan-activity; sid:100002806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lindnerelektroanlagen.de"; classtype:trojan-activity; sid:100002807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"linkintec.cn"; classtype:trojan-activity; sid:100002808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"liquidaz.casa"; classtype:trojan-activity; sid:100002809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"livetrack.in"; classtype:trojan-activity; sid:100002810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lloydsindian.co.uk"; classtype:trojan-activity; sid:100002811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lm.stagingarea.co.za"; classtype:trojan-activity; sid:100002812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lmaancha.co.il"; classtype:trojan-activity; sid:100002813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.cstdevs.com"; classtype:trojan-activity; sid:100002814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.login2.in"; classtype:trojan-activity; sid:100002815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"location-voitures.ma"; classtype:trojan-activity; sid:100002816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"login.trezor.com.stockfootagesindia.com"; classtype:trojan-activity; sid:100002817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"logotypfabriken.se"; classtype:trojan-activity; sid:100002818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotix.de"; classtype:trojan-activity; sid:100002819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotusanddragonfly.com"; classtype:trojan-activity; sid:100002820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.definerisco.com"; classtype:trojan-activity; sid:100002821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.difusodesign.com"; classtype:trojan-activity; sid:100002822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.quama.pe"; classtype:trojan-activity; sid:100002823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luckybrownie.com"; classtype:trojan-activity; sid:100002824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luminouspneuma.com"; classtype:trojan-activity; sid:100002825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luxomodels.com"; classtype:trojan-activity; sid:100002826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m-technics.kz"; classtype:trojan-activity; sid:100002827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m.estudiomoros.com.ar"; classtype:trojan-activity; sid:100002828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m.mobilelocalsales.com"; classtype:trojan-activity; sid:100002829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m.softsharks.com"; classtype:trojan-activity; sid:100002830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"madicon.co.za"; classtype:trojan-activity; sid:100002831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"magianegramagiablancayamarres.com"; classtype:trojan-activity; sid:100002832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maharaniworld.com"; classtype:trojan-activity; sid:100002833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.bs-eiendomme.co.za"; classtype:trojan-activity; sid:100002834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.golimoapp.com"; classtype:trojan-activity; sid:100002835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.jeffsono.org"; classtype:trojan-activity; sid:100002836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maksi.feb.unib.ac.id"; classtype:trojan-activity; sid:100002837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malaya.tv"; classtype:trojan-activity; sid:100002838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malwarecoding.github.io"; classtype:trojan-activity; sid:100002839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managed.oss-cn-beijing.aliyuncs.com"; classtype:trojan-activity; sid:100002840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managemysalon.in"; classtype:trojan-activity; sid:100002841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manantialesdelnorte.uy"; classtype:trojan-activity; sid:100002842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mangalyaa.lk"; classtype:trojan-activity; sid:100002843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manhtien.net"; classtype:trojan-activity; sid:100002844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marcapinyo.ru"; classtype:trojan-activity; sid:100002845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mario-sunjic.com"; classtype:trojan-activity; sid:100002846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariobrown.net"; classtype:trojan-activity; sid:100002847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariotessarollo.com"; classtype:trojan-activity; sid:100002848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketinfosales.com"; classtype:trojan-activity; sid:100002849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marksidfgs.ug"; classtype:trojan-activity; sid:100002850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"masjidhabeebiyarazviya.mysunni.com"; classtype:trojan-activity; sid:100002851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mastersofclientretention.com.au"; classtype:trojan-activity; sid:100002852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"masterthedaybook.com"; classtype:trojan-activity; sid:100002853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"materialescantu.com"; classtype:trojan-activity; sid:100002854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"matruchhaya.co.in"; classtype:trojan-activity; sid:100002855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maxiquim.cl"; classtype:trojan-activity; sid:100002856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maxoprint.co.uk"; classtype:trojan-activity; sid:100002857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maxtox.com.pk"; classtype:trojan-activity; sid:100002858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbgrm.com"; classtype:trojan-activity; sid:100002859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbjtimes.com"; classtype:trojan-activity; sid:100002860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbsolutions.ge"; classtype:trojan-activity; sid:100002861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbx.com.au"; classtype:trojan-activity; sid:100002862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mdasa.elin.co.za"; classtype:trojan-activity; sid:100002863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medevlb.org"; classtype:trojan-activity; sid:100002864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"media-server.skyinternet.com.pk"; classtype:trojan-activity; sid:100002865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medianews.ge"; classtype:trojan-activity; sid:100002866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mediawaysnews.com"; classtype:trojan-activity; sid:100002867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medistaffconsulting.com"; classtype:trojan-activity; sid:100002868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meeweb.com"; classtype:trojan-activity; sid:100002869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"megagynreformas.com.br"; classtype:trojan-activity; sid:100002870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"megamart.afnan-amc.com"; classtype:trojan-activity; sid:100002871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mehainteriors.com"; classtype:trojan-activity; sid:100002872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"melissaleiteestetica.com.br"; classtype:trojan-activity; sid:100002873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mercabits.com"; classtype:trojan-activity; sid:100002874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"merkathink.com"; classtype:trojan-activity; sid:100002875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mertlog.com"; classtype:trojan-activity; sid:100002876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"metaflip.io"; classtype:trojan-activity; sid:100002877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"metalin-cr.com"; classtype:trojan-activity; sid:100002878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mettaanand.org"; classtype:trojan-activity; sid:100002879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meuoculosnanet.com.br"; classtype:trojan-activity; sid:100002880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mfevr.com"; classtype:trojan-activity; sid:100002881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot.myvnc.com"; classtype:trojan-activity; sid:100002882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot80.myvnc.com"; classtype:trojan-activity; sid:100002883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"micalle.com.au"; classtype:trojan-activity; sid:100002884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michaelphilip.com"; classtype:trojan-activity; sid:100002885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michimal2.000webhostapp.com"; classtype:trojan-activity; sid:100002886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microblading.mirliandias.com.br"; classtype:trojan-activity; sid:100002887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microcomm-group.com"; classtype:trojan-activity; sid:100002888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mikhailmotoringschool.com"; classtype:trojan-activity; sid:100002889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mills-skyla30ec.com"; classtype:trojan-activity; sid:100002890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mingguanwms.com"; classtype:trojan-activity; sid:100002891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"minuevavida.org"; classtype:trojan-activity; sid:100002892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mirror.mypage.sk"; classtype:trojan-activity; sid:100002893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"misterson.com"; classtype:trojan-activity; sid:100002894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mkontakt.az"; classtype:trojan-activity; sid:100002895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mktf.mx"; classtype:trojan-activity; sid:100002896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mmdx.com"; classtype:trojan-activity; sid:100002897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mmogollon.com.mx"; classtype:trojan-activity; sid:100002898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mncarteam.com"; classtype:trojan-activity; sid:100002899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mobile.illumetechnology.com"; classtype:trojan-activity; sid:100002900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modelhouseturkey.com"; classtype:trojan-activity; sid:100002901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modernmanna.org"; classtype:trojan-activity; sid:100002902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"monetization.business"; classtype:trojan-activity; sid:100002903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"moninediy.com"; classtype:trojan-activity; sid:100002904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mopai.sg"; classtype:trojan-activity; sid:100002905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"moreirawag.ac.ug"; classtype:trojan-activity; sid:100002906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"motorcomunicacion.com"; classtype:trojan-activity; sid:100002907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"msacontabil.com.br"; classtype:trojan-activity; sid:100002908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mtspsmjeli.sch.id"; classtype:trojan-activity; sid:100002909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mumgee.co.za"; classtype:trojan-activity; sid:100002910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mundialdebienes.net"; classtype:trojan-activity; sid:100002911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mundotecnologiasolar.com"; classtype:trojan-activity; sid:100002912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"musaffirtours.com"; classtype:trojan-activity; sid:100002913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"muzimbiti.xigubo.co.mz"; classtype:trojan-activity; sid:100002914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mxpiqw.am.files.1drv.com"; classtype:trojan-activity; sid:100002915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mydatebook.in"; classtype:trojan-activity; sid:100002916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mymlql.com"; classtype:trojan-activity; sid:100002917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myritz.vettickal.com"; classtype:trojan-activity; sid:100002918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mysalons.in"; classtype:trojan-activity; sid:100002919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myscape.in"; classtype:trojan-activity; sid:100002920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mysura.it"; classtype:trojan-activity; sid:100002921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"naeemacademy.com"; classtype:trojan-activity; sid:100002922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"namnyak.co.ke"; classtype:trojan-activity; sid:100002923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nap.mgsservers.com"; classtype:trojan-activity; sid:100002924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"narcissisto.com"; classtype:trojan-activity; sid:100002925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"narimohol.com"; classtype:trojan-activity; sid:100002926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"navayurveda.in"; classtype:trojan-activity; sid:100002927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nec-i.com"; classtype:trojan-activity; sid:100002928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nedkellymyanmar.com"; classtype:trojan-activity; sid:100002929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nelitrianggraeni.000webhostapp.com"; classtype:trojan-activity; sid:100002930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nellaimasthanbiryani.com"; classtype:trojan-activity; sid:100002931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nerve.untergrund.net"; classtype:trojan-activity; sid:100002932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nettube.com.br"; classtype:trojan-activity; sid:100002933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"networkwheels.co.za"; classtype:trojan-activity; sid:100002934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neuroenergy.fahadjutt.com"; classtype:trojan-activity; sid:100002935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neuromedic.com.br"; classtype:trojan-activity; sid:100002936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newfuture.fr"; classtype:trojan-activity; sid:100002937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newinfinitysynergy.com"; classtype:trojan-activity; sid:100002938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newtreedesign.co.uk"; classtype:trojan-activity; sid:100002939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newvisionopticallab.com"; classtype:trojan-activity; sid:100002940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newxing.com"; classtype:trojan-activity; sid:100002941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nextdigitalday.ru"; classtype:trojan-activity; sid:100002942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ngdaycare.co.za"; classtype:trojan-activity; sid:100002943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nguyenkekhuyen.com"; classtype:trojan-activity; sid:100002944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nhorangtreem.com"; classtype:trojan-activity; sid:100002945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nicolas.ug"; classtype:trojan-activity; sid:100002946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nidhi.iexist.in"; classtype:trojan-activity; sid:100002947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nikanpolimer.ir"; classtype:trojan-activity; sid:100002948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilehouse.co.ug"; classtype:trojan-activity; sid:100002949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilinkeji.com"; classtype:trojan-activity; sid:100002950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nimboohomes.com"; classtype:trojan-activity; sid:100002951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"njtiledesigncenter.com"; classtype:trojan-activity; sid:100002952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nobius.org"; classtype:trojan-activity; sid:100002953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nocalnoodle.elin.co.za"; classtype:trojan-activity; sid:100002954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nomadicbees.com"; classtype:trojan-activity; sid:100002955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"notamuzikaletleri.com"; classtype:trojan-activity; sid:100002956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ns1.the-widyantos.com"; classtype:trojan-activity; sid:100002957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nsb.org.uk"; classtype:trojan-activity; sid:100002958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nurmarkaz.org"; classtype:trojan-activity; sid:100002959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nxtnet.ga"; classtype:trojan-activity; sid:100002960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nyasabigbullets.com"; classtype:trojan-activity; sid:100002961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nyeh2o.com.au"; classtype:trojan-activity; sid:100002962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oakleyandfriends.co.uk"; classtype:trojan-activity; sid:100002963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"obseques-conseils.com"; classtype:trojan-activity; sid:100002964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oecteam.com"; classtype:trojan-activity; sid:100002965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohe.ie"; classtype:trojan-activity; sid:100002966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohsewgorgeous.co.uk"; classtype:trojan-activity; sid:100002967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oknoplastik.sk"; classtype:trojan-activity; sid:100002968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oleholeh.memangbeda.website"; classtype:trojan-activity; sid:100002969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaia.org"; classtype:trojan-activity; sid:100002970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaromatic.com"; classtype:trojan-activity; sid:100002971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omega.az"; classtype:trojan-activity; sid:100002972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oms.pappai.com"; classtype:trojan-activity; sid:100002973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omscoc.pappai.com"; classtype:trojan-activity; sid:100002974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedigitalcard.granvizionnecorp.com"; classtype:trojan-activity; sid:100002975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedrive.listifyapp.co"; classtype:trojan-activity; sid:100002976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"online.creedglobal.in"; classtype:trojan-activity; sid:100002977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onlinestatis.bar"; classtype:trojan-activity; sid:100002978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"open.rawntech.com"; classtype:trojan-activity; sid:100002979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"open.warehousesaas.co.uk"; classtype:trojan-activity; sid:100002980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"opentoronto.org"; classtype:trojan-activity; sid:100002981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"opolis.io"; classtype:trojan-activity; sid:100002982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"opticaoptigral.cl"; classtype:trojan-activity; sid:100002983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"optimus.com.sg"; classtype:trojan-activity; sid:100002984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"order.bizpeed.com"; classtype:trojan-activity; sid:100002985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orientgatewayltd.com"; classtype:trojan-activity; sid:100002986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orion445.com"; classtype:trojan-activity; sid:100002987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oserve.pk"; classtype:trojan-activity; sid:100002988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ot.weenets.com"; classtype:trojan-activity; sid:100002989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"otolithenrichment.fahadjutt.com"; classtype:trojan-activity; sid:100002990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"outletdosaquecedores.com.br"; classtype:trojan-activity; sid:100002991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ozemag.com"; classtype:trojan-activity; sid:100002992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p1.lingpao8.com"; classtype:trojan-activity; sid:100002993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p3.zbjimg.com"; classtype:trojan-activity; sid:100002994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p6.zbjimg.com"; classtype:trojan-activity; sid:100002995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pablobrothel.com.ar"; classtype:trojan-activity; sid:100002996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacificgroup.ws"; classtype:trojan-activity; sid:100002997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacwebdesigns.com"; classtype:trojan-activity; sid:100002998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pagos.krayem.com.mx"; classtype:trojan-activity; sid:100002999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"palbas.cl"; classtype:trojan-activity; sid:100003000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"palochusvet.szm.com"; classtype:trojan-activity; sid:100003001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pamperpartypros.co.za"; classtype:trojan-activity; sid:100003002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parallel.rockvideos.at"; classtype:trojan-activity; sid:100003003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parejasfelices.mi-fs.com"; classtype:trojan-activity; sid:100003004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parkhussion.com"; classtype:trojan-activity; sid:100003005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"partharaj.me"; classtype:trojan-activity; sid:100003006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"partsapp.com.br"; classtype:trojan-activity; sid:100003007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pastorpaulocosta.com"; classtype:trojan-activity; sid:100003008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.51lg.com"; classtype:trojan-activity; sid:100003009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.99ddd.com"; classtype:trojan-activity; sid:100003010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch3.99ddd.com"; classtype:trojan-activity; sid:100003011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paths.elin.co.za"; classtype:trojan-activity; sid:100003012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patriotsupremehemp.com"; classtype:trojan-activity; sid:100003013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paulmercier.biz"; classtype:trojan-activity; sid:100003014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payerrealty.com"; classtype:trojan-activity; sid:100003015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payments.atifsiddiqui.me"; classtype:trojan-activity; sid:100003016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pcsoori.com"; classtype:trojan-activity; sid:100003017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pd.oceaniarp.net"; classtype:trojan-activity; sid:100003018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pemdodo.com"; classtype:trojan-activity; sid:100003019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perfumeriamontes.es"; classtype:trojan-activity; sid:100003020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"periodiche.bar"; classtype:trojan-activity; sid:100003021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpus.onlineman7-jombang.sch.id"; classtype:trojan-activity; sid:100003022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpustekim.untirta.ac.id"; classtype:trojan-activity; sid:100003023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pestoclean.co.uk"; classtype:trojan-activity; sid:100003024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"petercollie.com"; classtype:trojan-activity; sid:100003025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"petroindia.co.in"; classtype:trojan-activity; sid:100003026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ph4s.ru"; classtype:trojan-activity; sid:100003027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phasdesign.com"; classtype:trojan-activity; sid:100003028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phenhuong.sanpham.online"; classtype:trojan-activity; sid:100003029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phittc.com"; classtype:trojan-activity; sid:100003030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"photo360.kubooking.com"; classtype:trojan-activity; sid:100003031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pink99.com"; classtype:trojan-activity; sid:100003032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pinkpaprika.co.uk"; classtype:trojan-activity; sid:100003033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"plasfan.ind.br"; classtype:trojan-activity; sid:100003034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"platinumherbal.com"; classtype:trojan-activity; sid:100003035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"playground2.grupoaliadasca.com"; classtype:trojan-activity; sid:100003036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pmglance.startwriteup.com"; classtype:trojan-activity; sid:100003037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pointactionsg.com"; classtype:trojan-activity; sid:100003038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pokojewewladyslawowie.pl"; classtype:trojan-activity; sid:100003039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pole.com.vc"; classtype:trojan-activity; sid:100003040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ponchokhana.com"; classtype:trojan-activity; sid:100003041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pool.phxdir.com"; classtype:trojan-activity; sid:100003042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pooltablemoversdenver.net"; classtype:trojan-activity; sid:100003043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"portal.premiumpunch.com"; classtype:trojan-activity; sid:100003044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"posmicrosystems.com"; classtype:trojan-activity; sid:100003045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"poulman.panagiotopoulos-tours.gr"; classtype:trojan-activity; sid:100003046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ppdb.smk-ciptaskill.sch.id"; classtype:trojan-activity; sid:100003047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestasicash.com.ar"; classtype:trojan-activity; sid:100003048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestigehomeautomation.net"; classtype:trojan-activity; sid:100003049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"preview2.behalen.com"; classtype:trojan-activity; sid:100003050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prishaartcreations.com"; classtype:trojan-activity; sid:100003051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prismaxis.com"; classtype:trojan-activity; sid:100003052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"production.sparshims.com"; classtype:trojan-activity; sid:100003053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"programaoperadoronline.com.br"; classtype:trojan-activity; sid:100003054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"project.exquitec.com"; classtype:trojan-activity; sid:100003055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promotapp.com"; classtype:trojan-activity; sid:100003056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promotoradescomplica.com.br"; classtype:trojan-activity; sid:100003057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promoversdubai.com"; classtype:trojan-activity; sid:100003058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq.elin.co.za"; classtype:trojan-activity; sid:100003059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq2.elin.co.za"; classtype:trojan-activity; sid:100003060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosoc.nl"; classtype:trojan-activity; sid:100003061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosupport.cl"; classtype:trojan-activity; sid:100003062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosyarmakassar.com"; classtype:trojan-activity; sid:100003063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"provence.elin.co.za"; classtype:trojan-activity; sid:100003064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prueba.danielluza.com"; classtype:trojan-activity; sid:100003065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pujashoppe.in"; classtype:trojan-activity; sid:100003066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punchdialogues.com"; classtype:trojan-activity; sid:100003067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punjabdevelopersassociation.com.pk"; classtype:trojan-activity; sid:100003068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pvcprinting.co.uk"; classtype:trojan-activity; sid:100003069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qadir.tickfa.ir"; classtype:trojan-activity; sid:100003070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qatarglobalconsulting.com"; classtype:trojan-activity; sid:100003071; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qmsled.com"; classtype:trojan-activity; sid:100003072; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"quartier-midi.be"; classtype:trojan-activity; sid:100003073; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"querocar.com"; classtype:trojan-activity; sid:100003074; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rachmat-assuhaimi.my.id"; classtype:trojan-activity; sid:100003075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"radioafifense.deploys.live"; classtype:trojan-activity; sid:100003076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rainbowisp.info"; classtype:trojan-activity; sid:100003077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rajeshtailang.com"; classtype:trojan-activity; sid:100003078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rakeshkhatri.in"; classtype:trojan-activity; sid:100003079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"raodigitalmedia.com"; classtype:trojan-activity; sid:100003080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"raquelhelena.com.br"; classtype:trojan-activity; sid:100003081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rarlabarchiver.ac"; classtype:trojan-activity; sid:100003082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rasadbar.ir"; classtype:trojan-activity; sid:100003083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rashika.ascarvalho.co.za"; classtype:trojan-activity; sid:100003084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ratemyfenancialadvisor.com"; classtype:trojan-activity; sid:100003085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ravenproductionsltd.com"; classtype:trojan-activity; sid:100003086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rc.ixiaoyang.cn"; classtype:trojan-activity; sid:100003087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rcmesilva.charbelsales.com.br"; classtype:trojan-activity; sid:100003088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reacredit.com.br"; classtype:trojan-activity; sid:100003089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"readymmade.com"; classtype:trojan-activity; sid:100003090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"recyclethesurplus.com"; classtype:trojan-activity; sid:100003091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"redbats.co.in"; classtype:trojan-activity; sid:100003092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"redchillicrackers.com"; classtype:trojan-activity; sid:100003093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reifenquick.de"; classtype:trojan-activity; sid:100003094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"relaxindulge.co.nz"; classtype:trojan-activity; sid:100003095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"renehavis.com.ua"; classtype:trojan-activity; sid:100003096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"repatriacioncolombia.com"; classtype:trojan-activity; sid:100003097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"res.uf1.cn"; classtype:trojan-activity; sid:100003098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reseller.digimitra.in"; classtype:trojan-activity; sid:100003099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reseller.itechbrasil.com"; classtype:trojan-activity; sid:100003100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"resuco.net"; classtype:trojan-activity; sid:100003101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rezkabum.ru"; classtype:trojan-activity; sid:100003102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rhema.com.sg"; classtype:trojan-activity; sid:100003103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"richmondminerals.co.zm"; classtype:trojan-activity; sid:100003104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinaefoundation.org.za"; classtype:trojan-activity; sid:100003105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinkaisystem-ht.com"; classtype:trojan-activity; sid:100003106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"riverfox.co.za"; classtype:trojan-activity; sid:100003107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkcable.co.in"; classtype:trojan-activity; sid:100003108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkverify.securestudies.com"; classtype:trojan-activity; sid:100003109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertmcardle.com"; classtype:trojan-activity; sid:100003110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertsinclair.net"; classtype:trojan-activity; sid:100003111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ronnietucker.co.uk"; classtype:trojan-activity; sid:100003112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roomsvc.servegate.kr"; classtype:trojan-activity; sid:100003113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roshnijewellery.com"; classtype:trojan-activity; sid:100003114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rsgym.net"; classtype:trojan-activity; sid:100003115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubazar.pro"; classtype:trojan-activity; sid:100003116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubycityvietnam.com"; classtype:trojan-activity; sid:100003117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruisgood.ru"; classtype:trojan-activity; sid:100003118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruwadalkuwait.com"; classtype:trojan-activity; sid:100003119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rydchile.cl"; classtype:trojan-activity; sid:100003120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.thechinesemuslim.com"; classtype:trojan-activity; sid:100003121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sac2.11xii.com"; classtype:trojan-activity; sid:100003122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sacredscentsonline.com"; classtype:trojan-activity; sid:100003123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sadmahfuneralservices.co.za"; classtype:trojan-activity; sid:100003124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safcol-colors.com"; classtype:trojan-activity; sid:100003125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safehubsecurity.ca"; classtype:trojan-activity; sid:100003126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safety.nanotechproautocare.com"; classtype:trojan-activity; sid:100003127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sahathaikasetpan.com"; classtype:trojan-activity; sid:100003128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sainzim.co.za"; classtype:trojan-activity; sid:100003129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"saisoftwareinc.com"; classtype:trojan-activity; sid:100003130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"salecorner.yourpageserver.com"; classtype:trojan-activity; sid:100003131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"salonsaifa.com"; classtype:trojan-activity; sid:100003132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"samriddhijyotish.com"; classtype:trojan-activity; sid:100003133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sandovalgraphics.com"; classtype:trojan-activity; sid:100003134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"santyago.org"; classtype:trojan-activity; sid:100003135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sasystemsuk.com"; classtype:trojan-activity; sid:100003136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scaladevelopments.scaladevco.com"; classtype:trojan-activity; sid:100003137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scarfaceindustries.com"; classtype:trojan-activity; sid:100003138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scglobal.co.th"; classtype:trojan-activity; sid:100003139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schalke04rss.de"; classtype:trojan-activity; sid:100003140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scheff.com"; classtype:trojan-activity; sid:100003141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schoolbustracker.softgig.co.ke"; classtype:trojan-activity; sid:100003142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sculetus.nl"; classtype:trojan-activity; sid:100003143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"secure-doc-reader.com"; classtype:trojan-activity; sid:100003144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"segalsmetals.elin.co.za"; classtype:trojan-activity; sid:100003145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sellmyphonela.com"; classtype:trojan-activity; sid:100003146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"selltechtoday.com"; classtype:trojan-activity; sid:100003147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"senbiaojita.com"; classtype:trojan-activity; sid:100003148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sentierodelviandante.ml"; classtype:trojan-activity; sid:100003149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"serendibsourcing.com"; classtype:trojan-activity; sid:100003150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sericaasia.com"; classtype:trojan-activity; sid:100003151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd.myvnc.com"; classtype:trojan-activity; sid:100003152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd80.myvnc.com"; classtype:trojan-activity; sid:100003153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"serviciovirtual.com.ar"; classtype:trojan-activity; sid:100003154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sexologistpakistan.net"; classtype:trojan-activity; sid:100003155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"seyranikenger.com.tr"; classtype:trojan-activity; sid:100003156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sgb.ac.ke"; classtype:trojan-activity; sid:100003157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sgessy.com.br"; classtype:trojan-activity; sid:100003158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shaheentbfoundation.com"; classtype:trojan-activity; sid:100003159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shahikhana.cstdevs.com"; classtype:trojan-activity; sid:100003160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shahu66.com"; classtype:trojan-activity; sid:100003161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharkrigs.com"; classtype:trojan-activity; sid:100003162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharpelevators.in"; classtype:trojan-activity; sid:100003163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shembefoundation.com"; classtype:trojan-activity; sid:100003164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shivakunwar.com.np"; classtype:trojan-activity; sid:100003165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shoblasaathitrust.org"; classtype:trojan-activity; sid:100003166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shooka-co.com"; classtype:trojan-activity; sid:100003167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shop.goldspot.agency"; classtype:trojan-activity; sid:100003168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shopsofe.com"; classtype:trojan-activity; sid:100003169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shrinikelectrical.co.za"; classtype:trojan-activity; sid:100003170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sibernetix.fr"; classtype:trojan-activity; sid:100003171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sige.brisainformatica.com.br"; classtype:trojan-activity; sid:100003172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"signatureads.co.in"; classtype:trojan-activity; sid:100003173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siili.net"; classtype:trojan-activity; sid:100003174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simoneporzi.it"; classtype:trojan-activity; sid:100003175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simorsint.com"; classtype:trojan-activity; sid:100003176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simplithy.co.uk"; classtype:trojan-activity; sid:100003177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindicato1ucm.cl"; classtype:trojan-activity; sid:100003178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindpol.tiejuris.com.br"; classtype:trojan-activity; sid:100003179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sinergidwireka.com"; classtype:trojan-activity; sid:100003180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sipahielektrik.com"; classtype:trojan-activity; sid:100003181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sistelligent.com"; classtype:trojan-activity; sid:100003182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skare.net"; classtype:trojan-activity; sid:100003183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyflyfares.com"; classtype:trojan-activity; sid:100003184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyscan.com"; classtype:trojan-activity; sid:100003185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smarthouseforum.ru"; classtype:trojan-activity; sid:100003186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smartzedu.com"; classtype:trojan-activity; sid:100003187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smokesolutionindia.com"; classtype:trojan-activity; sid:100003188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smritiphotography.in"; classtype:trojan-activity; sid:100003189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sobariko.com"; classtype:trojan-activity; sid:100003190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sobethuacademy.com"; classtype:trojan-activity; sid:100003191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.110route.com"; classtype:trojan-activity; sid:100003192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.officelabo.net"; classtype:trojan-activity; sid:100003193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"softanis.net"; classtype:trojan-activity; sid:100003194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sogecoenergy.com"; classtype:trojan-activity; sid:100003195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sohs.conceptechs.info"; classtype:trojan-activity; sid:100003196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"solar.amazingtribe.lk"; classtype:trojan-activity; sid:100003197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somcorbera.cat"; classtype:trojan-activity; sid:100003198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somir.com.mx"; classtype:trojan-activity; sid:100003199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soralapps.com"; classtype:trojan-activity; sid:100003200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sota-france.fr"; classtype:trojan-activity; sid:100003201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"space.proactint.org"; classtype:trojan-activity; sid:100003202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spaceframe.mobi.space-frame.co.za"; classtype:trojan-activity; sid:100003203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"special-key.cf"; classtype:trojan-activity; sid:100003204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spent.com.pl"; classtype:trojan-activity; sid:100003205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spetsesyachtcharter.gr"; classtype:trojan-activity; sid:100003206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spiritualroot.org"; classtype:trojan-activity; sid:100003207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spititourism.com"; classtype:trojan-activity; sid:100003208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spittinfire.com"; classtype:trojan-activity; sid:100003209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sports-net.de"; classtype:trojan-activity; sid:100003210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"src1.minibai.com"; classtype:trojan-activity; sid:100003211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sreenivasapaintingworks.com"; classtype:trojan-activity; sid:100003212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sriglobalit.com"; classtype:trojan-activity; sid:100003213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"srilankamovies.com"; classtype:trojan-activity; sid:100003214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"srvmanos.no-ip.info"; classtype:trojan-activity; sid:100003215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ss.monita.co.id"; classtype:trojan-activity; sid:100003216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"st.devcodin.com"; classtype:trojan-activity; sid:100003217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"staging.apparelpunch.com"; classtype:trojan-activity; sid:100003218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"starcountry.net"; classtype:trojan-activity; sid:100003219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"static.3001.net"; classtype:trojan-activity; sid:100003220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stiau.iuc.ac"; classtype:trojan-activity; sid:100003221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sticker.jewsjuice.com"; classtype:trojan-activity; sid:100003222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stiepancasetia.ac.id"; classtype:trojan-activity; sid:100003223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stlukesohag.com"; classtype:trojan-activity; sid:100003224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"store.ericalgarin.com"; classtype:trojan-activity; sid:100003225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stott-thompson.co.uk"; classtype:trojan-activity; sid:100003226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stratexec.co.za"; classtype:trojan-activity; sid:100003227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"suboldesign.com"; classtype:trojan-activity; sid:100003228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sumerians.org"; classtype:trojan-activity; sid:100003229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunaryem.com.tr"; classtype:trojan-activity; sid:100003230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunbrero.com.au"; classtype:trojan-activity; sid:100003231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunmarkholidays.com"; classtype:trojan-activity; sid:100003232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"supermercadostia.com"; classtype:trojan-activity; sid:100003233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support-4-free.com"; classtype:trojan-activity; sid:100003234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support.clz.kr"; classtype:trojan-activity; sid:100003235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"supportit.online"; classtype:trojan-activity; sid:100003236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sw.yourpageserver.com"; classtype:trojan-activity; sid:100003237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweaty.dk"; classtype:trojan-activity; sid:100003238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweet-diet.com"; classtype:trojan-activity; sid:100003239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swiftlogisticseg.com"; classtype:trojan-activity; sid:100003240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swwbia.com"; classtype:trojan-activity; sid:100003241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"syracusecoffee.com"; classtype:trojan-activity; sid:100003242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sytraders.co"; classtype:trojan-activity; sid:100003243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"t.honker.info"; classtype:trojan-activity; sid:100003244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"t.netcatkit.com"; classtype:trojan-activity; sid:100003245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tacticohosting.com"; classtype:trojan-activity; sid:100003246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tadoo.ca"; classtype:trojan-activity; sid:100003247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tafsantoursandtravels.com"; classtype:trojan-activity; sid:100003248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tajushariya.com"; classtype:trojan-activity; sid:100003249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tallyinvoicecustomization.com"; classtype:trojan-activity; sid:100003250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taltus.co.uk"; classtype:trojan-activity; sid:100003251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tapalkoedacoffee.com"; classtype:trojan-activity; sid:100003252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tarravalleyfoods.com.au"; classtype:trojan-activity; sid:100003253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taurus.ug"; classtype:trojan-activity; sid:100003254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tavo.cl"; classtype:trojan-activity; sid:100003255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taxicabsrilanka.com"; classtype:trojan-activity; sid:100003256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tc.snpsresidential.com"; classtype:trojan-activity; sid:100003257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tcy.198424.com"; classtype:trojan-activity; sid:100003258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tdsp.yngw518.com"; classtype:trojan-activity; sid:100003259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tech332.synology.me"; classtype:trojan-activity; sid:100003260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"techgms.com"; classtype:trojan-activity; sid:100003261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teduae.com"; classtype:trojan-activity; sid:100003262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teleargentina.com"; classtype:trojan-activity; sid:100003263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"telescopelms.com"; classtype:trojan-activity; sid:100003264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tencoconsulting.com"; classtype:trojan-activity; sid:100003265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teneth.co.za"; classtype:trojan-activity; sid:100003266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tentandoserfitness.000webhostapp.com"; classtype:trojan-activity; sid:100003267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tessrobins.com"; classtype:trojan-activity; sid:100003268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.adventser.com"; classtype:trojan-activity; sid:100003269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.letraele.es"; classtype:trojan-activity; sid:100003270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.lubrico.in"; classtype:trojan-activity; sid:100003271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.typoten.com"; classtype:trojan-activity; sid:100003272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.wanepghana.org"; classtype:trojan-activity; sid:100003273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.asistencia247.com"; classtype:trojan-activity; sid:100003274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.milenial.id"; classtype:trojan-activity; sid:100003275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.tenplusone.my"; classtype:trojan-activity; sid:100003276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.basis-web.com"; classtype:trojan-activity; sid:100003277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.marrenconstruction.ie"; classtype:trojan-activity; sid:100003278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.clickitsolutionsmw.com"; classtype:trojan-activity; sid:100003279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.thinkingcorp.in"; classtype:trojan-activity; sid:100003280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testnew.yourpageserver.com"; classtype:trojan-activity; sid:100003281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testuat.itmoregistry.com"; classtype:trojan-activity; sid:100003282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teteaffiche.stephanebillon.com"; classtype:trojan-activity; sid:100003283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tewoerd.eu"; classtype:trojan-activity; sid:100003284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"textile.softberg.ro"; classtype:trojan-activity; sid:100003285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tharringtonsponsorship.com"; classtype:trojan-activity; sid:100003286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theatretalkies.in"; classtype:trojan-activity; sid:100003287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecleaningladiespdx.com"; classtype:trojan-activity; sid:100003288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecreativecafe.co.uk"; classtype:trojan-activity; sid:100003289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thedesertship.com"; classtype:trojan-activity; sid:100003290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thediasporianexperience.com"; classtype:trojan-activity; sid:100003291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thefirmlawgroup.com.au"; classtype:trojan-activity; sid:100003292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thefuturelife.in"; classtype:trojan-activity; sid:100003293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thehighlightinterior.com"; classtype:trojan-activity; sid:100003294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thekassia.co.uk"; classtype:trojan-activity; sid:100003295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"themansionkasauli.com"; classtype:trojan-activity; sid:100003296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theprofinn.com"; classtype:trojan-activity; sid:100003297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thesummitpc.net"; classtype:trojan-activity; sid:100003298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theurbantutors.com"; classtype:trojan-activity; sid:100003299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thirdstringcalifornia.com"; classtype:trojan-activity; sid:100003300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thosewebbs.com"; classtype:trojan-activity; sid:100003301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thriveink.com"; classtype:trojan-activity; sid:100003302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tianangdep.com"; classtype:trojan-activity; sid:100003303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickfoods.tickme.lk"; classtype:trojan-activity; sid:100003304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tienda.ventadigital.com.ar"; classtype:trojan-activity; sid:100003305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"timamollo.co.za"; classtype:trojan-activity; sid:100003306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"timegonebuy.com"; classtype:trojan-activity; sid:100003307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tksb.net"; classtype:trojan-activity; sid:100003308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tlcc.com.gt"; classtype:trojan-activity; sid:100003309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"todoapp.cstdevs.com"; classtype:trojan-activity; sid:100003310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"todocontodo.com.mx"; classtype:trojan-activity; sid:100003311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonydong.com"; classtype:trojan-activity; sid:100003312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonystram.com"; classtype:trojan-activity; sid:100003313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonyzone.com"; classtype:trojan-activity; sid:100003314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tooba.tenplusone.my"; classtype:trojan-activity; sid:100003315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tools.reimclub.com"; classtype:trojan-activity; sid:100003316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topcell9.com"; classtype:trojan-activity; sid:100003317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toplevel.com.br"; classtype:trojan-activity; sid:100003318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topmask.co.za"; classtype:trojan-activity; sid:100003319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"torresquinterocorp.com"; classtype:trojan-activity; sid:100003320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toyotacollege.ac.th"; classtype:trojan-activity; sid:100003321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpef.lsoftdemo.com"; classtype:trojan-activity; sid:100003322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpke.hu"; classtype:trojan-activity; sid:100003323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"translaterjemah.com"; classtype:trojan-activity; sid:100003324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"travelwithmanta.co.za"; classtype:trojan-activity; sid:100003325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trendyshoes.co.za"; classtype:trojan-activity; sid:100003326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trezors.io.mahlongwa.com"; classtype:trojan-activity; sid:100003327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trimestre.bar"; classtype:trojan-activity; sid:100003328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"triplonet.com.br"; classtype:trojan-activity; sid:100003329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"troki.com.co"; classtype:trojan-activity; sid:100003330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tropics.codeleek.net"; classtype:trojan-activity; sid:100003331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trudelfavreau.com"; classtype:trojan-activity; sid:100003332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tsd.jxwan.com"; classtype:trojan-activity; sid:100003333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tulli.info"; classtype:trojan-activity; sid:100003334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tupperware.michaelroberge.ca"; classtype:trojan-activity; sid:100003335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"turanggaresources.com"; classtype:trojan-activity; sid:100003336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"txtdust.com"; classtype:trojan-activity; sid:100003337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uat.indianfilmzone.com"; classtype:trojan-activity; sid:100003338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ublretailerdemo.cstdevs.com"; classtype:trojan-activity; sid:100003339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uc-56.ru"; classtype:trojan-activity; sid:100003340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uisusa.uisusa.com"; classtype:trojan-activity; sid:100003341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ultimate-24.de"; classtype:trojan-activity; sid:100003342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"umwelt-kirchhof.de"; classtype:trojan-activity; sid:100003343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unicorpbrunei.com"; classtype:trojan-activity; sid:100003344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uniengrisb.com"; classtype:trojan-activity; sid:100003345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unisoftcc.com"; classtype:trojan-activity; sid:100003346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unyazitelecom.com"; classtype:trojan-activity; sid:100003347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"upcbpta.com"; classtype:trojan-activity; sid:100003348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"urbantrapfest.cl"; classtype:trojan-activity; sid:100003349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"usamyforever.azureedge.net"; classtype:trojan-activity; sid:100003350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"used-jeans.fr"; classtype:trojan-activity; sid:100003351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"useformoney.000webhostapp.com"; classtype:trojan-activity; sid:100003352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"usmadetshirts.com"; classtype:trojan-activity; sid:100003353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uss.ac.th"; classtype:trojan-activity; sid:100003354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uzzepay.com.br"; classtype:trojan-activity; sid:100003355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vanzare.cabanabrazi2.ro"; classtype:trojan-activity; sid:100003356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vbcargo.hu"; classtype:trojan-activity; sid:100003357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vcah.co.uk"; classtype:trojan-activity; sid:100003358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vectarts.com"; classtype:trojan-activity; sid:100003359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vegadelcasero.cl"; classtype:trojan-activity; sid:100003360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"velma-harber30ku.com"; classtype:trojan-activity; sid:100003361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vendas.lidiacarmeli.com.br"; classtype:trojan-activity; sid:100003362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"versualstudio.com"; classtype:trojan-activity; sid:100003363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"veterinariadrpopui.com"; classtype:trojan-activity; sid:100003364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vfocus.net"; classtype:trojan-activity; sid:100003365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vienen.gblix.srv.br"; classtype:trojan-activity; sid:100003366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vilaart.rs"; classtype:trojan-activity; sid:100003367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villamarand.com"; classtype:trojan-activity; sid:100003368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villatera.com"; classtype:trojan-activity; sid:100003369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"violinstop.com"; classtype:trojan-activity; sid:100003370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"virtuleverage.com"; classtype:trojan-activity; sid:100003371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visions.alnisamart.com"; classtype:trojan-activity; sid:100003372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visualhome.cl"; classtype:trojan-activity; sid:100003373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vitoriamodaintima.com.br"; classtype:trojan-activity; sid:100003374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vivationdesign.com"; classtype:trojan-activity; sid:100003375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"viveirodoiscorregos.com.br"; classtype:trojan-activity; sid:100003376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vksales.com"; classtype:trojan-activity; sid:100003377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vocalterra.com"; classtype:trojan-activity; sid:100003378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vokasi.ub.ac.id"; classtype:trojan-activity; sid:100003379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vologroup.com.br"; classtype:trojan-activity; sid:100003380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"voteyouramerica.dekitout.com"; classtype:trojan-activity; sid:100003381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vpinversiones.cl"; classtype:trojan-activity; sid:100003382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vpts.co.za"; classtype:trojan-activity; sid:100003383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vstsample.com"; classtype:trojan-activity; sid:100003384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vtube.fadlymotivator.com"; classtype:trojan-activity; sid:100003385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vvsskmodinationalschool.com"; classtype:trojan-activity; sid:100003386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu"; classtype:trojan-activity; sid:100003387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepliberia.org"; classtype:trojan-activity; sid:100003388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepniger.org"; classtype:trojan-activity; sid:100003389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weareactum.com"; classtype:trojan-activity; sid:100003390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.eng.ubu.ac.th"; classtype:trojan-activity; sid:100003391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.geetle.ga"; classtype:trojan-activity; sid:100003392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.geomegasoft.net"; classtype:trojan-activity; sid:100003393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.newinnovationtechnology.com"; classtype:trojan-activity; sid:100003394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.smarts-works.com"; classtype:trojan-activity; sid:100003395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.thebeessolution.com"; classtype:trojan-activity; sid:100003396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webgis.perumdasolo.com"; classtype:trojan-activity; sid:100003397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webmailwindstreamnetmessagesecureapp1rqr.ga"; classtype:trojan-activity; sid:100003398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webpresario.com"; classtype:trojan-activity; sid:100003399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"website-work.com"; classtype:trojan-activity; sid:100003400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weinsteincounseling.com"; classtype:trojan-activity; sid:100003401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wfinance.com.br"; classtype:trojan-activity; sid:100003402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whcms.yourpageserver.com"; classtype:trojan-activity; sid:100003403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whiteresponse.com"; classtype:trojan-activity; sid:100003404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wi522012.ferozo.com"; classtype:trojan-activity; sid:100003405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wikalen.co.za"; classtype:trojan-activity; sid:100003406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildnights.co.uk"; classtype:trojan-activity; sid:100003407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildtrust.mediadevstaging.com"; classtype:trojan-activity; sid:100003408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"willow-nettica.com"; classtype:trojan-activity; sid:100003409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wimbamusica.com"; classtype:trojan-activity; sid:100003410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"windcomtechnologies.com"; classtype:trojan-activity; sid:100003411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wishesconcierge.com"; classtype:trojan-activity; sid:100003412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woezon.agency"; classtype:trojan-activity; sid:100003413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wolfgang-brodte.de"; classtype:trojan-activity; sid:100003414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wonderhawaii.com"; classtype:trojan-activity; sid:100003415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woodsytech.com"; classtype:trojan-activity; sid:100003416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wordpress.saleensuporte.com.br"; classtype:trojan-activity; sid:100003417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"workingsolutionsrome.org"; classtype:trojan-activity; sid:100003418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wozata.000webhostapp.com"; classtype:trojan-activity; sid:100003419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wp.readhere.in"; classtype:trojan-activity; sid:100003420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wpdemo.101clients.com.au"; classtype:trojan-activity; sid:100003421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"writtendeer.com"; classtype:trojan-activity; sid:100003422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ws5588.f3322.net"; classtype:trojan-activity; sid:100003423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wsdyrmtcntlfarmtwsvb.dns.army"; classtype:trojan-activity; sid:100003424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wyklej.pl"; classtype:trojan-activity; sid:100003425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"x-iting.de"; classtype:trojan-activity; sid:100003426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"x2vn.com"; classtype:trojan-activity; sid:100003427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xia.beihaixue.com"; classtype:trojan-activity; sid:100003428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xixaoclothing.com"; classtype:trojan-activity; sid:100003429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xk.996is.com"; classtype:trojan-activity; sid:100003430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--80akinnkiib6h.xn--90ais"; classtype:trojan-activity; sid:100003431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--polimerbizmimarlk-rvc.com"; classtype:trojan-activity; sid:100003432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ybom.urbanolab.com"; classtype:trojan-activity; sid:100003433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yeichner.com"; classtype:trojan-activity; sid:100003434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ylfpremium.com"; classtype:trojan-activity; sid:100003435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yoast.yourpageserver.com"; classtype:trojan-activity; sid:100003436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yourclub1.com"; classtype:trojan-activity; sid:100003437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yourtopdog.com.au"; classtype:trojan-activity; sid:100003438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"youtubetrainingacademy.com"; classtype:trojan-activity; sid:100003439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yskadvisors.com"; classtype:trojan-activity; sid:100003440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yummyyogaudaipur.com"; classtype:trojan-activity; sid:100003441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yzkzixun.com"; classtype:trojan-activity; sid:100003442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zmedcoach.com"; classtype:trojan-activity; sid:100003443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zytrox.tk"; classtype:trojan-activity; sid:100003444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zz.690tx.com"; classtype:trojan-activity; sid:100003445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100003446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/86.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100003447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c64.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100003448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; endswith; nocase; http.host; content:"amumufree.weebly.com"; classtype:trojan-activity; sid:100003449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/proxyi.exe"; endswith; nocase; http.host; content:"analogx.com"; classtype:trojan-activity; sid:100003450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvdfv/anjj/downloads/jami.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/johnhast/efve/downloads/versiumr.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/johnhast/efve/downloads/versiumrr.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/4.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/6.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labesoftware/update/downloads/boost-fps.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labesoftware/update/downloads/install_plugin_x64_x86.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labesoftware/update/downloads/vpn_free.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/clr.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatev.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/work.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/component.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/regsvc.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skygaming/updates/downloads/update.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/001.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1488.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1_cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1fc2d.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003471; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/26a5.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003472; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003473; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/abjects.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003474; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/attached.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003475; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/b7f2c.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003476; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/battletext.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003477; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003478; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003479; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003480; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_makros.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003481; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_silent.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003482; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_sup.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003483; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003484; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003485; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003486; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildss.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003487; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientnik.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003488; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientrevers.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003489; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dcrat.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003490; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hans.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hulu.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfive.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfour.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelone.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelthree.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/inteltwo.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/kleiman.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/notepadplus.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/putty.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/rockethcd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/scvhost900.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/sessionwin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003511; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/siliculose.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003512; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/statemobi.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003513; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003514; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stgedo.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/svcperf.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurjok.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurusbabac.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/telekiller.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateandr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/vhajeja.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/word.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/www.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/xlsd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hmatrix/data/hack1226.exe"; endswith; nocase; http.host; content:"cd.textfiles.com"; classtype:trojan-activity; sid:100003529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/816070119281131570/816070273254162442/all.txt"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/825372018244583454/826848185246023750/loaddd.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/825372018244583454/826848348342059008/zeppelin.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/825372018244583454/826848405258633277/build.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/826198252025675816/826537386485612574/china.png"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/razor/rzr-winner_intro.zip"; endswith; nocase; http.host; content:"chiptune.com"; classtype:trojan-activity; sid:100003538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100003539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100003540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meteoradminz/hidden-tear/zip/master"; endswith; nocase; http.host; content:"codeload.github.com"; classtype:trojan-activity; sid:100003541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; endswith; nocase; http.host; content:"colfincas.com"; classtype:trojan-activity; sid:100003542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qz0h69.pdf"; endswith; nocase; http.host; content:"deepfreedom.org"; classtype:trojan-activity; sid:100003543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ktcghnmcwws43wzscphukbfnwtuaxidx&revid=0b8z0b7_i5sirk2xrtehmstg0vxvit3b4n3lmbdrdrjrodndrpq"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100003544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; endswith; nocase; http.host; content:"drive.google.com.it-barcelona.com"; classtype:trojan-activity; sid:100003545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=12khl-unz2np4q54b2jgpwlsh6cuz0pss"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=13sfskplrox3d7uantwjj_trs6ciwvqa1"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=152yoztzpbx_bbpxepfackfklg8c1eao6"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=15hcgek7odccdafzf-9gvibnlgkirj4uo"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=194lqzukzvt-jtdxmihcvhd0yk1sxoybk"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1br5iufkkmmfeipqo3ecviqykbcdgcnio"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1cos43rmscrescxk3u40qjuqbwr-pydsn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1dnm3wtjf6ud5fv6zop9cvbr4rs2of1-n"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1dqin1sdd6rbah3sggzsxzeqgrkmhjnqm"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1fensc6gc0fww0gbevsrnwwnlajypzdvv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1htinwtfrw1wc3_ma8odztnq0qpnic2q6"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1jkov2g5s1xkcq4bfb3uvmd6inhadatrg"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1jnarxelz8gtbkg5pa_s0rc8kv3ejkepn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1kjcylye1dbmhystyyotz-3pagktkhlhq"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1lsv4sko083sywwjndgqnsh_6sgqodqtu"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1mwgdd3lxuuk-bnsrm1rpclom0cmx7wob"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1nmf6kty3xsoygjxjhb-bsafvlfy-0lt2"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1p5fvqkxzwoiu_uauzbmrxpklsetculad"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1q1dwckludrpqijtrpw14_60d5nu7n97t"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1r9f9irwhutxozsbp2h9erd_a7fa2pwko"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1s221a6wpx6i7nfrztnhh9priojtybuxq"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1sjvkrinuscxqmbkdeusxaezazbiagnv3"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1so1trfuzt5-giahetghfhmd-_ot3rq35"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1uowridpynurgqlgqjbtgramigo2a9v76"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vjq92eqivh01yxmal20whl2es3ld6nxb"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yqpuxjbnjokc5fjgt-8xzuybr97rtvg2"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ywkgalidldb32pio6ywmbyvdk7oar3yy"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/1zilg/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100003599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/qcgfmfvh/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100003600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/emclick.zip"; endswith; nocase; http.host; content:"e-mudhra.com"; classtype:trojan-activity; sid:100003601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100003602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100003603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100003604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; endswith; nocase; http.host; content:"file.elecfans.com"; classtype:trojan-activity; sid:100003609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100003610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100003611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; endswith; nocase; http.host; content:"gist.githubusercontent.com"; classtype:trojan-activity; sid:100003612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7991.js"; endswith; nocase; http.host; content:"hostingcloud.racing"; classtype:trojan-activity; sid:100003613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; endswith; nocase; http.host; content:"hqdecig.com"; classtype:trojan-activity; sid:100003614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/suy/"; endswith; nocase; http.host; content:"hsecaravans.co.uk"; classtype:trojan-activity; sid:100003615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19/items/startup_20210219/startup.txt"; endswith; nocase; http.host; content:"ia801802.us.archive.org"; classtype:trojan-activity; sid:100003616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/online-timer-kvhxz/ilxl/"; endswith; nocase; http.host; content:"ie-best.net"; classtype:trojan-activity; sid:100003617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100003618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100003619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ebook/cs17.exe"; endswith; nocase; http.host; content:"jcedu.org"; classtype:trojan-activity; sid:100003620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100003621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100003622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100003623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; endswith; nocase; http.host; content:"karmakoincodes.weebly.com"; classtype:trojan-activity; sid:100003624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dg/etrac/nf4emwz/"; endswith; nocase; http.host; content:"kotakwarna.co.id"; classtype:trojan-activity; sid:100003625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe"; endswith; nocase; http.host; content:"ksh.hu"; classtype:trojan-activity; sid:100003626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/affiliate/kuaizip_setup_10029.exe"; endswith; nocase; http.host; content:"kuaizip.com"; classtype:trojan-activity; sid:100003627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linuxforensicscode.zip"; endswith; nocase; http.host; content:"linuxforensicsbook.com.s3.amazonaws.com"; classtype:trojan-activity; sid:100003628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ds/1802.gif"; endswith; nocase; http.host; content:"marcostrombetta.com.br"; classtype:trojan-activity; sid:100003629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k/big5/1giof6/"; endswith; nocase; http.host; content:"minpic.de"; classtype:trojan-activity; sid:100003630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-contentbak/t9m/"; endswith; nocase; http.host; content:"morrobaydrugandgift.com"; classtype:trojan-activity; sid:100003631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ds/0204.gif"; endswith; nocase; http.host; content:"moumitas.com"; classtype:trojan-activity; sid:100003632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; endswith; nocase; http.host; content:"my.cloudme.com"; classtype:trojan-activity; sid:100003633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/aacenc.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100003634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/doxillionsetup.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100003635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/4/1/6/6/4166984/keygen.exe"; endswith; nocase; http.host; content:"newyarlfm.weebly.com"; classtype:trojan-activity; sid:100003636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; endswith; nocase; http.host; content:"nhipcauytevietnhat.com"; classtype:trojan-activity; sid:100003637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; endswith; nocase; http.host; content:"note.youdao.com"; classtype:trojan-activity; sid:100003638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; endswith; nocase; http.host; content:"oldschoolvalue.s3.amazonaws.com"; classtype:trojan-activity; sid:100003639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21108&authkey=acq44gahejhwrag"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d!184&authkey=ackbiiarirejcam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d%21184&authkey=ackbiiarirejcam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0!1667&authkey=an8otd7jzc7xgho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0%211667&authkey=an8otd7jzc7xgho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0da4ace18aa7d1e2&resid=da4ace18aa7d1e2%21131&authkey=adjn1y5pp4a10_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f!286&authkey=almwisomhv3c0zc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!140&authkey=apn44x6bxlzq3ac"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!151&authkey=aeuk7knodrpenek"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!153&authkey=ao6e8g0bzbp_idw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!154&authkey=ah4chedbotzpmtq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!156&authkey=ajnqscnmrdonpkg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21140&authkey=apn44x6bxlzq3ac"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21151&authkey=aeuk7knodrpenek"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21153&authkey=ao6e8g0bzbp_idw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21154&authkey=ah4chedbotzpmtq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21156&authkey=ajnqscnmrdonpkg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2968c371f5450503&resid=2968c371f5450503!122&authkey=aaqhhxbnwfwrz28"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1!223&authkey=aajr842bzum0yg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3ee68228c34c236d&resid=3ee68228c34c236d%21129&authkey=apll6hu3-xetzxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba!2203&authkey=ajvalmr5l8epwvm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba%212203&authkey=ajvalmr5l8epwvm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21141&authkey=aazwaw2xjms24o0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21198&authkey=akq4jrbjm6spd9m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!109&authkey=ap-okubj9bvtlc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21106&authkey=an9dhtmtufpis-m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21109&authkey=ap-okubj9bvtlc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2!517&authkey=akfewcyiwlwomyk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21517&authkey=akfewcyiwlwomyk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!301&authkey=abquzhtdjg5pryk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!302&authkey=al2_xstzqulnnqw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6!305&authkey=an-uuhplpk2zp5u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21301&authkey=abquzhtdjg5pryk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21302&authkey=al2_xstzqulnnqw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21305&authkey=an-uuhplpk2zp5u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!106&authkey=ahu5s4ttjvxbnxo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!107&authkey=abj3eccentbeaqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!108&authkey=amvcygo4prlgt4i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe!110&authkey=ahzuehvk5nvzo90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21106&authkey=ahu5s4ttjvxbnxo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21107&authkey=abj3eccentbeaqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21108&authkey=amvcygo4prlgt4i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7621307c0282fefe&resid=7621307c0282fefe%21110&authkey=ahzuehvk5nvzo90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125570&authkey=aejqgjglwurnb0a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21444&authkey=abzxvycu0ggtmg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=89360b4c7415c088&resid=89360b4c7415c088%21106&authkey=akfcfq3zq5oof2i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=89360b4c7415c088&resid=89360b4c7415c088%21108&authkey=amfbkmapqbvzpvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!254&authkey=ajt5wxegbvzbwqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!255&authkey=aaimhpp89qmcfhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33%21254&authkey=ajt5wxegbvzbwqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!112&authkey=af43qpcgl0t2f5o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a31988151cf6813e&resid=a31988151cf6813e%21107&authkey=ab9lanzt1aj_0ws"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21256&authkey=aapnly5qifymcvw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818!129&authkey=aesewk3cf5vbrxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818%21129&authkey=aesewk3cf5vbrxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1047&authkey=aod6jbxyicq2v4g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004071; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211047&authkey=aod6jbxyicq2v4g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004072; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004073; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004074; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cda6c13b54bbe48c&resid=cda6c13b54bbe48c!44331&authkey=afohia-wo-alwiy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cda6c13b54bbe48c&resid=cda6c13b54bbe48c%2144331&authkey=afohia-wo-alwiy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d4d413b6e7cf7088&resid=d4d413b6e7cf7088%211271&authkey=akz65bxpgvdxjb8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2!1818&authkey=anh2wga7qmhbmuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e0837d627665c3e2&resid=e0837d627665c3e2%211818&authkey=anh2wga7qmhbmuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2!107&authkey=af-bicrg1c6vgck"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2%21107&authkey=af-bicrg1c6vgck"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e627fc797baa3032&resid=e627fc797baa3032!2324&authkey=aa8i-r7ixmcraha"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e627fc797baa3032&resid=e627fc797baa3032%212324&authkey=aa8i-r7ixmcraha"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8!148&authkey=agjcwq650c8wdbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8!150&authkey=ami5aqoinvosjle"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8%21148&authkey=agjcwq650c8wdbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e8a5ad7ff91ed1b8&resid=e8a5ad7ff91ed1b8%21150&authkey=ami5aqoinvosjle"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ef7cc06ce7ffafb8&resid=ef7cc06ce7ffafb8%21108&authkey=anmpeqm9gm_zv9m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!226&authkey=adho6klfkjflaqk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!229&authkey=akvo12quxgcwnk8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!234&authkey=abhyu_zfy6bhwmu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21226&authkey=adho6klfkjflaqk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21234&authkey=abhyu_zfy6bhwmu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c!115&authkey=adbcrakskolznjq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c%21115&authkey=adbcrakskolznjq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f75d6b103b974e4c&resid=f75d6b103b974e4c%21116&authkey=anenotuhbsni0zu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fd67fafc46d3c687&resid=fd67fafc46d3c687%21473&authkey=aoid_cp-jgffqvm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21848&authkey=ag1_e421v-t5r9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!198&authkey=amg468jpljbyyky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21198&authkey=amg468jpljbyyky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100004226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r/a39ev"; endswith; nocase; http.host; content:"paste.ee"; classtype:trojan-activity; sid:100004227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/77jhk0iw"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100004228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/89hkc7wb"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100004229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/yqvsvlvq"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100004230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/llc/mwcacs65xienqdp/"; endswith; nocase; http.host; content:"pierreconsulting.info"; classtype:trojan-activity; sid:100004231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bayesian-forecasting-amj5e/s5hqmf6/"; endswith; nocase; http.host; content:"pioneiraagronegocio.com.br"; classtype:trojan-activity; sid:100004232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skoda22.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100004233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100004234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; endswith; nocase; http.host; content:"qjbutterflyevents.co.za"; classtype:trojan-activity; sid:100004235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dhlshipmentawb80326979402.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100004236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maersk-bl+draft-copy-shipping-documents.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100004237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/po+for+april+shipment.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100004238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zenar.exe"; endswith; nocase; http.host; content:"racisa.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100004239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myqseeaccount/one/main/one.htm"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tennc/webshell/master/other/small_shell.txt"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; endswith; nocase; http.host; content:"res.yeshen.com"; classtype:trojan-activity; sid:100004251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/q05z91"; endswith; nocase; http.host; content:"sendspace.com"; classtype:trojan-activity; sid:100004252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ey4lpx8rx.zip"; endswith; nocase; http.host; content:"shribharatvatika.com"; classtype:trojan-activity; sid:100004253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; endswith; nocase; http.host; content:"sites.google.com"; classtype:trojan-activity; sid:100004254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-nurse-ss8d9/z/"; endswith; nocase; http.host; content:"technologydistilled.com"; classtype:trojan-activity; sid:100004264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/23.exe"; endswith; nocase; http.host; content:"tsrv4.ws"; classtype:trojan-activity; sid:100004265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crisanar/defis/jek_crackme1.7.zip"; endswith; nocase; http.host; content:"users.skynet.be"; classtype:trojan-activity; sid:100004266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/amowvegfrt9ja/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100004267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100004268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100004269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100004270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb%5efr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb^fr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/151_155/tidex_-_short_stuff.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syria-files/attach/222/222051_instruction.zip"; endswith; nocase; http.host; content:"wikileaks.org"; classtype:trojan-activity; sid:100004276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/common/yz.vbs"; endswith; nocase; http.host; content:"yp.hnggzyjy.cn"; classtype:trojan-activity; sid:100004277; rev:1;) diff --git a/urlhaus-filter-unbound-online.conf b/urlhaus-filter-unbound-online.conf index 69fdf868..a4a5e57a 100644 --- a/urlhaus-filter-unbound-online.conf +++ b/urlhaus-filter-unbound-online.conf @@ -1,5 +1,5 @@ # Title: Online Malicious Domains Unbound Blocklist -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -16,7 +16,6 @@ local-zone: "360.lcy2zzx.pw" always_nxdomain local-zone: "360down7.miiyun.cn" always_nxdomain local-zone: "77st.net" always_nxdomain local-zone: "8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com" always_nxdomain -local-zone: "87du.vip" always_nxdomain local-zone: "8poieq.bn.files.1drv.com" always_nxdomain local-zone: "aatreefelling.co.za" always_nxdomain local-zone: "abad.tv" always_nxdomain @@ -77,6 +76,7 @@ local-zone: "anadelgbt.org" always_nxdomain local-zone: "anantam.net.in" always_nxdomain local-zone: "andreelapeyre.com" always_nxdomain local-zone: "andremaraisbeleggings.co.za" always_nxdomain +local-zone: "andreonemaia.com" always_nxdomain local-zone: "andres.ac.ug" always_nxdomain local-zone: "andres.ug" always_nxdomain local-zone: "andreshconcejal.solucioneslink.com" always_nxdomain @@ -86,7 +86,6 @@ local-zone: "angloteste.bigprime.com.br" always_nxdomain local-zone: "anhung1102.vn" always_nxdomain local-zone: "anurontv.com" always_nxdomain local-zone: "anysbergbiltong.co.za" always_nxdomain -local-zone: "apartamentoscitta.com" always_nxdomain local-zone: "api-ms.cobainaja.id" always_nxdomain local-zone: "api.cstdevs.com" always_nxdomain local-zone: "api.quocbao.biz" always_nxdomain @@ -109,15 +108,17 @@ local-zone: "atlasconcreteworks.com" always_nxdomain local-zone: "attach.66rpg.com" always_nxdomain local-zone: "atteuqpotentialunlimited.com" always_nxdomain local-zone: "augustair.com" always_nxdomain +local-zone: "aulist.com" always_nxdomain +local-zone: "automaticrefreshments.com" always_nxdomain local-zone: "avadhanagames.com" always_nxdomain local-zone: "ayahuascasp.com.br" always_nxdomain local-zone: "ayamallah.com" always_nxdomain +local-zone: "aycconsultoriaempresarial.com" always_nxdomain local-zone: "azmeasurement.com" always_nxdomain local-zone: "b2b.toptanakaryakit.com.tr" always_nxdomain local-zone: "backgrounds.pk" always_nxdomain local-zone: "badeggdesign.com" always_nxdomain local-zone: "balealgodon.mx" always_nxdomain -local-zone: "ballina.andrewmaughan.com" always_nxdomain local-zone: "bangkok-orchids.com" always_nxdomain local-zone: "bangladeshunbound.com" always_nxdomain local-zone: "bary.sz4h.com" always_nxdomain @@ -128,6 +129,7 @@ local-zone: "bbia.co.uk" always_nxdomain local-zone: "bcmt.elin.co.za" always_nxdomain local-zone: "bcrg.co.za" always_nxdomain local-zone: "bdnextrend.xyz" always_nxdomain +local-zone: "beanx88.xyz" always_nxdomain local-zone: "bearcatpumps.com.cn" always_nxdomain local-zone: "beautincollagen.rs" always_nxdomain local-zone: "bekape.co.id" always_nxdomain @@ -135,6 +137,7 @@ local-zone: "beor360.com" always_nxdomain local-zone: "bespokeweddings.ie" always_nxdomain local-zone: "bestcarenepal.com" always_nxdomain local-zone: "betone.co.kr" always_nxdomain +local-zone: "betycopaints.com" always_nxdomain local-zone: "beveragesmiami.solucioneslink.com" always_nxdomain local-zone: "bhavaniengineering.com" always_nxdomain local-zone: "bigmikesupplies.co.za" always_nxdomain @@ -163,6 +166,7 @@ local-zone: "bophelocare.co.za" always_nxdomain local-zone: "bounces.mi-fs.com" always_nxdomain local-zone: "boutiqueofferte.com" always_nxdomain local-zone: "bpo.correct.go.th" always_nxdomain +local-zone: "bradleyinstitute.co.za" always_nxdomain local-zone: "brandtrust.com.pk" always_nxdomain local-zone: "braunfinancial.com.au" always_nxdomain local-zone: "brendanquine.com" always_nxdomain @@ -213,6 +217,7 @@ local-zone: "chezalice.co.za" always_nxdomain local-zone: "childselect.com" always_nxdomain local-zone: "chinhdropfile.myvnc.com" always_nxdomain local-zone: "chinhdropfile80.myvnc.com" always_nxdomain +local-zone: "chipmania.it" always_nxdomain local-zone: "cible-energy.com" always_nxdomain local-zone: "cifeer.net" always_nxdomain local-zone: "cirugiadenarizbucaramanga.com" always_nxdomain @@ -226,10 +231,9 @@ local-zone: "cloud.fc.co.mz" always_nxdomain local-zone: "cm-arquitetos.com" always_nxdomain local-zone: "codsambal.com" always_nxdomain local-zone: "colempaques.info" always_nxdomain -local-zone: "colinde.pricesne.com" always_nxdomain local-zone: "colorpak.pl" always_nxdomain +local-zone: "columbia.aula-web.net" always_nxdomain local-zone: "community.reimclub.com" always_nxdomain -local-zone: "comosairdoburaco.com.br" always_nxdomain local-zone: "competancy.indigoconsult.net" always_nxdomain local-zone: "conceptimagine.ro" always_nxdomain local-zone: "config.cqhbkjzx.com" always_nxdomain @@ -245,7 +249,6 @@ local-zone: "covid19.cyberschool.or.id" always_nxdomain local-zone: "cpanel.shivay.net" always_nxdomain local-zone: "cr-sq.com" always_nxdomain local-zone: "craftech.nxtnet.ga" always_nxdomain -local-zone: "crearechile.cl" always_nxdomain local-zone: "creationskateboards.com" always_nxdomain local-zone: "crecerco.com" always_nxdomain local-zone: "crittersbythebay.com" always_nxdomain @@ -255,7 +258,6 @@ local-zone: "crmroche.manivelasst.com" always_nxdomain local-zone: "crscorretordeimoveis.com.br" always_nxdomain local-zone: "cse-engineer.com" always_nxdomain local-zone: "csnserver.com" always_nxdomain -local-zone: "ctracknxt.in" always_nxdomain local-zone: "cubescargoexpress.com" always_nxdomain local-zone: "curasoles.co.za" always_nxdomain local-zone: "currantmedia.com" always_nxdomain @@ -274,7 +276,6 @@ local-zone: "data.cdevelop.org" always_nxdomain local-zone: "data.over-blog-kiwi.com" always_nxdomain local-zone: "datapolish.com" always_nxdomain local-zone: "dating.khokhas.co.za" always_nxdomain -local-zone: "datsom.vn" always_nxdomain local-zone: "davethompson.me.uk" always_nxdomain local-zone: "davidmcguinness.info" always_nxdomain local-zone: "dayspringdaisies.com" always_nxdomain @@ -298,7 +299,6 @@ local-zone: "destinymc.co.za" always_nxdomain local-zone: "detorre.es" always_nxdomain local-zone: "dev.sebpo.net" always_nxdomain local-zone: "dev.watch-store.eu" always_nxdomain -local-zone: "dezcom.com" always_nxdomain local-zone: "dfcf.91756.cn" always_nxdomain local-zone: "dfsfcsfcdsfsdvcfsvcscv.com" always_nxdomain local-zone: "diamantenegro.mi-fs.com" always_nxdomain @@ -313,6 +313,7 @@ local-zone: "dl.installcdn-aws.com" always_nxdomain local-zone: "dl.packetstormsecurity.net" always_nxdomain local-zone: "dl.rina-roleplay.com" always_nxdomain local-zone: "dnn.alibuf.com" always_nxdomain +local-zone: "dns.alibuf.com" always_nxdomain local-zone: "dns.cyberium.cc" always_nxdomain local-zone: "dockerupdate.anondns.net" always_nxdomain local-zone: "docman.orientalservices.in" always_nxdomain @@ -329,6 +330,8 @@ local-zone: "dosame.com" always_nxdomain local-zone: "dosman.pl" always_nxdomain local-zone: "dovberger.com" always_nxdomain local-zone: "down.pcclear.com" always_nxdomain +local-zone: "down.postch-de.top" always_nxdomain +local-zone: "down.postch-dl.top" always_nxdomain local-zone: "down.udashi.com" always_nxdomain local-zone: "down.webbora.com" always_nxdomain local-zone: "down1.arpun.com" always_nxdomain @@ -388,14 +391,13 @@ local-zone: "extrovertoffers.com" always_nxdomain local-zone: "f1sol.com" always_nxdomain local-zone: "fahrzeugdrive.com" always_nxdomain local-zone: "familydentist.site" always_nxdomain -local-zone: "faveraprojects.com" always_nxdomain local-zone: "fc.co.mz" always_nxdomain local-zone: "felicienne.nl" always_nxdomain local-zone: "files.martellexpress.us" always_nxdomain local-zone: "filmotainment.com" always_nxdomain local-zone: "final.makkahkmcc.com" always_nxdomain local-zone: "fineartgallerym.com" always_nxdomain -local-zone: "fisconline.casa" always_nxdomain +local-zone: "fisconline.bar" always_nxdomain local-zone: "fix-america-now.org" always_nxdomain local-zone: "fixauto.illumetechnology.com" always_nxdomain local-zone: "fixturegovernment.com" always_nxdomain @@ -410,7 +412,6 @@ local-zone: "foothills.com.br" always_nxdomain local-zone: "footweardirect.elin.co.za" always_nxdomain local-zone: "forum.mdb.nu" always_nxdomain local-zone: "fotoobjetivo.com" always_nxdomain -local-zone: "foundationrepairhoustontx.net" always_nxdomain local-zone: "foxeps.com.br" always_nxdomain local-zone: "fraud.bpcbankingtech.com" always_nxdomain local-zone: "freecnetdownload.com" always_nxdomain @@ -419,7 +420,6 @@ local-zone: "ftp.n3twork30cm.ml" always_nxdomain local-zone: "fullelectronica.com.ar" always_nxdomain local-zone: "funletters.net" always_nxdomain local-zone: "fusionfiresolutions.com" always_nxdomain -local-zone: "futbolpr.com" always_nxdomain local-zone: "futuregraphics.com.ar" always_nxdomain local-zone: "g.pinmonkey.xyz" always_nxdomain local-zone: "gametwogame.com" always_nxdomain @@ -436,6 +436,7 @@ local-zone: "ghettohub.co.za" always_nxdomain local-zone: "ghislain.dartois.pagesperso-orange.fr" always_nxdomain local-zone: "giadungg7.com" always_nxdomain local-zone: "giddos.ga" always_nxdomain +local-zone: "giteletropical.com" always_nxdomain local-zone: "glowinmedia.co.ke" always_nxdomain local-zone: "gmsebpl.com" always_nxdomain local-zone: "gmtransformationacademy.com" always_nxdomain @@ -448,6 +449,7 @@ local-zone: "goldcoastoffice365.com" always_nxdomain local-zone: "goldcoastoffice365.com.au" always_nxdomain local-zone: "golden-memories-funerals.yourpageserver.com" always_nxdomain local-zone: "goldenasiacapital.com" always_nxdomain +local-zone: "goldmen.in" always_nxdomain local-zone: "gorecycle.fahadjutt.com" always_nxdomain local-zone: "gpotecnosystems.com" always_nxdomain local-zone: "gracejukes.com" always_nxdomain @@ -476,13 +478,12 @@ local-zone: "hhaward.org" always_nxdomain local-zone: "highlandroadcoc.com" always_nxdomain local-zone: "highlandslasvegas.atakdev.com" always_nxdomain local-zone: "hindi.factsriver.com" always_nxdomain -local-zone: "hiptool.net" always_nxdomain local-zone: "hitpe.com" always_nxdomain local-zone: "hitstation.nl" always_nxdomain +local-zone: "hlmd.in" always_nxdomain local-zone: "hmpmall.co.kr" always_nxdomain local-zone: "hoagietesting10.com" always_nxdomain local-zone: "hoayeuthuong-my.sharepoint.com" always_nxdomain -local-zone: "holmesservices.mobiledevsite.co" always_nxdomain local-zone: "homefindersolutions.com" always_nxdomain local-zone: "hongluosi.com" always_nxdomain local-zone: "hookedupboatclub.com" always_nxdomain @@ -493,7 +494,6 @@ local-zone: "houstonshutters.site" always_nxdomain local-zone: "hr2019.vrcom7.com" always_nxdomain local-zone: "hrnautica.com.br" always_nxdomain local-zone: "hseda.com" always_nxdomain -local-zone: "hsmwebapp.com" always_nxdomain local-zone: "htownbars.com" always_nxdomain local-zone: "hubtech.co.za" always_nxdomain local-zone: "huellacero.cl" always_nxdomain @@ -533,16 +533,19 @@ local-zone: "ioabc.wif.com.br" always_nxdomain local-zone: "ipmes.ma" always_nxdomain local-zone: "iremart.es" always_nxdomain local-zone: "iris101.co.uk" always_nxdomain +local-zone: "isaac.mikhailmotoringschool.com" always_nxdomain local-zone: "iscamenabe.com" always_nxdomain local-zone: "isiphephelocon.co.za" always_nxdomain local-zone: "iso-dubai.net" always_nxdomain local-zone: "israrulhaq.me" always_nxdomain +local-zone: "isrorg.com" always_nxdomain local-zone: "isso.ps" always_nxdomain local-zone: "ist-security.com" always_nxdomain local-zone: "it123.ru" always_nxdomain local-zone: "italiandirezione.casa" always_nxdomain local-zone: "itc-demo.softgig.co.ke" always_nxdomain local-zone: "itelsys.ma" always_nxdomain +local-zone: "itmotasaciones.com" always_nxdomain local-zone: "jacktech.jackindia.com" always_nxdomain local-zone: "jaishritours.com" always_nxdomain local-zone: "jamiekaylive.com" always_nxdomain @@ -556,6 +559,7 @@ local-zone: "jennwolfemtb.com" always_nxdomain local-zone: "jhayesconsulting.com" always_nxdomain local-zone: "jiaoyuzixun.cn" always_nxdomain local-zone: "jing-da.com.tw" always_nxdomain +local-zone: "jmtc.91756.cn" always_nxdomain local-zone: "jnanbharati.com" always_nxdomain local-zone: "jobs.thebeessolution.com" always_nxdomain local-zone: "joelbonissilver.com" always_nxdomain @@ -566,6 +570,7 @@ local-zone: "jumpmanualjacobhiller.com" always_nxdomain local-zone: "jupiter.toxsl.in" always_nxdomain local-zone: "justinscott.com.au" always_nxdomain local-zone: "kadigital.co.uk" always_nxdomain +local-zone: "kaizenjanitorial.com" always_nxdomain local-zone: "kalawatihomes.com" always_nxdomain local-zone: "kalogirosfinance.com" always_nxdomain local-zone: "kaptaanchapal.com" always_nxdomain @@ -627,14 +632,16 @@ local-zone: "lotusanddragonfly.com" always_nxdomain local-zone: "lp.definerisco.com" always_nxdomain local-zone: "lp.difusodesign.com" always_nxdomain local-zone: "lp.quama.pe" always_nxdomain -local-zone: "ltc.typoten.com" always_nxdomain +local-zone: "luckybrownie.com" always_nxdomain local-zone: "luminouspneuma.com" always_nxdomain local-zone: "luxomodels.com" always_nxdomain local-zone: "m-technics.kz" always_nxdomain local-zone: "m.estudiomoros.com.ar" always_nxdomain local-zone: "m.mobilelocalsales.com" always_nxdomain +local-zone: "m.softsharks.com" always_nxdomain local-zone: "madicon.co.za" always_nxdomain local-zone: "magianegramagiablancayamarres.com" always_nxdomain +local-zone: "maharaniworld.com" always_nxdomain local-zone: "mail.bs-eiendomme.co.za" always_nxdomain local-zone: "mail.golimoapp.com" always_nxdomain local-zone: "mail.jeffsono.org" always_nxdomain @@ -660,7 +667,6 @@ local-zone: "matruchhaya.co.in" always_nxdomain local-zone: "maxiquim.cl" always_nxdomain local-zone: "maxoprint.co.uk" always_nxdomain local-zone: "maxtox.com.pk" always_nxdomain -local-zone: "maybethescobar.com" always_nxdomain local-zone: "mbgrm.com" always_nxdomain local-zone: "mbjtimes.com" always_nxdomain local-zone: "mbsolutions.ge" always_nxdomain @@ -691,11 +697,12 @@ local-zone: "michaelphilip.com" always_nxdomain local-zone: "michimal2.000webhostapp.com" always_nxdomain local-zone: "microblading.mirliandias.com.br" always_nxdomain local-zone: "microcomm-group.com" always_nxdomain +local-zone: "mikhailmotoringschool.com" always_nxdomain +local-zone: "mills-skyla30ec.com" always_nxdomain local-zone: "mingguanwms.com" always_nxdomain local-zone: "minuevavida.org" always_nxdomain local-zone: "mirror.mypage.sk" always_nxdomain local-zone: "misterson.com" always_nxdomain -local-zone: "mixr.at" always_nxdomain local-zone: "mkontakt.az" always_nxdomain local-zone: "mktf.mx" always_nxdomain local-zone: "mmdx.com" always_nxdomain @@ -732,6 +739,7 @@ local-zone: "navayurveda.in" always_nxdomain local-zone: "nec-i.com" always_nxdomain local-zone: "nedkellymyanmar.com" always_nxdomain local-zone: "nelitrianggraeni.000webhostapp.com" always_nxdomain +local-zone: "nellaimasthanbiryani.com" always_nxdomain local-zone: "nerve.untergrund.net" always_nxdomain local-zone: "nettube.com.br" always_nxdomain local-zone: "networkwheels.co.za" always_nxdomain @@ -756,7 +764,6 @@ local-zone: "njtiledesigncenter.com" always_nxdomain local-zone: "nobius.org" always_nxdomain local-zone: "nocalnoodle.elin.co.za" always_nxdomain local-zone: "nomadicbees.com" always_nxdomain -local-zone: "nonnarina.ax" always_nxdomain local-zone: "notamuzikaletleri.com" always_nxdomain local-zone: "ns1.the-widyantos.com" always_nxdomain local-zone: "nsb.org.uk" always_nxdomain @@ -776,12 +783,15 @@ local-zone: "omaromatic.com" always_nxdomain local-zone: "omega.az" always_nxdomain local-zone: "oms.pappai.com" always_nxdomain local-zone: "omscoc.pappai.com" always_nxdomain +local-zone: "onedigitalcard.granvizionnecorp.com" always_nxdomain local-zone: "onedrive.listifyapp.co" always_nxdomain local-zone: "online.creedglobal.in" always_nxdomain local-zone: "onlinestatis.bar" always_nxdomain +local-zone: "open.rawntech.com" always_nxdomain local-zone: "open.warehousesaas.co.uk" always_nxdomain local-zone: "opentoronto.org" always_nxdomain local-zone: "opolis.io" always_nxdomain +local-zone: "opticaoptigral.cl" always_nxdomain local-zone: "optimus.com.sg" always_nxdomain local-zone: "order.bizpeed.com" always_nxdomain local-zone: "orientgatewayltd.com" always_nxdomain @@ -819,6 +829,7 @@ local-zone: "pcsoori.com" always_nxdomain local-zone: "pd.oceaniarp.net" always_nxdomain local-zone: "pemdodo.com" always_nxdomain local-zone: "perfumeriamontes.es" always_nxdomain +local-zone: "periodiche.bar" always_nxdomain local-zone: "perpus.onlineman7-jombang.sch.id" always_nxdomain local-zone: "perpustekim.untirta.ac.id" always_nxdomain local-zone: "pestoclean.co.uk" always_nxdomain @@ -838,6 +849,7 @@ local-zone: "pmglance.startwriteup.com" always_nxdomain local-zone: "pointactionsg.com" always_nxdomain local-zone: "pokojewewladyslawowie.pl" always_nxdomain local-zone: "pole.com.vc" always_nxdomain +local-zone: "ponchokhana.com" always_nxdomain local-zone: "pool.phxdir.com" always_nxdomain local-zone: "pooltablemoversdenver.net" always_nxdomain local-zone: "portal.premiumpunch.com" always_nxdomain @@ -848,6 +860,7 @@ local-zone: "prestasicash.com.ar" always_nxdomain local-zone: "prestigehomeautomation.net" always_nxdomain local-zone: "preview2.behalen.com" always_nxdomain local-zone: "prishaartcreations.com" always_nxdomain +local-zone: "prismaxis.com" always_nxdomain local-zone: "production.sparshims.com" always_nxdomain local-zone: "programaoperadoronline.com.br" always_nxdomain local-zone: "project.exquitec.com" always_nxdomain @@ -899,7 +912,6 @@ local-zone: "reseller.itechbrasil.com" always_nxdomain local-zone: "resuco.net" always_nxdomain local-zone: "rezkabum.ru" always_nxdomain local-zone: "rhema.com.sg" always_nxdomain -local-zone: "richancyber.info" always_nxdomain local-zone: "richmondminerals.co.zm" always_nxdomain local-zone: "rinaefoundation.org.za" always_nxdomain local-zone: "rinkaisystem-ht.com" always_nxdomain @@ -908,7 +920,6 @@ local-zone: "rkcable.co.in" always_nxdomain local-zone: "rkverify.securestudies.com" always_nxdomain local-zone: "robertmcardle.com" always_nxdomain local-zone: "robertsinclair.net" always_nxdomain -local-zone: "romanianpoints.com" always_nxdomain local-zone: "ronnietucker.co.uk" always_nxdomain local-zone: "roomsvc.servegate.kr" always_nxdomain local-zone: "roshnijewellery.com" always_nxdomain @@ -918,7 +929,6 @@ local-zone: "rubycityvietnam.com" always_nxdomain local-zone: "ruisgood.ru" always_nxdomain local-zone: "ruwadalkuwait.com" always_nxdomain local-zone: "rydchile.cl" always_nxdomain -local-zone: "s.51shijuan.com" always_nxdomain local-zone: "s.thechinesemuslim.com" always_nxdomain local-zone: "sac2.11xii.com" always_nxdomain local-zone: "sacredscentsonline.com" always_nxdomain @@ -952,7 +962,9 @@ local-zone: "serendibsourcing.com" always_nxdomain local-zone: "sericaasia.com" always_nxdomain local-zone: "servicemhkd.myvnc.com" always_nxdomain local-zone: "servicemhkd80.myvnc.com" always_nxdomain +local-zone: "serviciovirtual.com.ar" always_nxdomain local-zone: "sexologistpakistan.net" always_nxdomain +local-zone: "seyranikenger.com.tr" always_nxdomain local-zone: "sgb.ac.ke" always_nxdomain local-zone: "sgessy.com.br" always_nxdomain local-zone: "shaheentbfoundation.com" always_nxdomain @@ -1003,6 +1015,7 @@ local-zone: "spaceframe.mobi.space-frame.co.za" always_nxdomain local-zone: "special-key.cf" always_nxdomain local-zone: "spent.com.pl" always_nxdomain local-zone: "spetsesyachtcharter.gr" always_nxdomain +local-zone: "spiritualroot.org" always_nxdomain local-zone: "spititourism.com" always_nxdomain local-zone: "spittinfire.com" always_nxdomain local-zone: "sports-net.de" always_nxdomain @@ -1022,7 +1035,7 @@ local-zone: "stiepancasetia.ac.id" always_nxdomain local-zone: "stlukesohag.com" always_nxdomain local-zone: "store.ericalgarin.com" always_nxdomain local-zone: "stott-thompson.co.uk" always_nxdomain -local-zone: "streetdemo.yourpageserver.com" always_nxdomain +local-zone: "stratexec.co.za" always_nxdomain local-zone: "suboldesign.com" always_nxdomain local-zone: "sumerians.org" always_nxdomain local-zone: "sunaryem.com.tr" always_nxdomain @@ -1070,6 +1083,7 @@ local-zone: "test.lubrico.in" always_nxdomain local-zone: "test.typoten.com" always_nxdomain local-zone: "test.wanepghana.org" always_nxdomain local-zone: "test1.asistencia247.com" always_nxdomain +local-zone: "test1.milenial.id" always_nxdomain local-zone: "test1.tenplusone.my" always_nxdomain local-zone: "test2.basis-web.com" always_nxdomain local-zone: "test2.marrenconstruction.ie" always_nxdomain @@ -1094,7 +1108,7 @@ local-zone: "themansionkasauli.com" always_nxdomain local-zone: "theprofinn.com" always_nxdomain local-zone: "thesummitpc.net" always_nxdomain local-zone: "theurbantutors.com" always_nxdomain -local-zone: "thientu.net" always_nxdomain +local-zone: "thirdstringcalifornia.com" always_nxdomain local-zone: "thosewebbs.com" always_nxdomain local-zone: "thriveink.com" always_nxdomain local-zone: "tianangdep.com" always_nxdomain @@ -1104,7 +1118,6 @@ local-zone: "timamollo.co.za" always_nxdomain local-zone: "timegonebuy.com" always_nxdomain local-zone: "tksb.net" always_nxdomain local-zone: "tlcc.com.gt" always_nxdomain -local-zone: "tntmedia.gr" always_nxdomain local-zone: "todoapp.cstdevs.com" always_nxdomain local-zone: "todocontodo.com.mx" always_nxdomain local-zone: "tonydong.com" always_nxdomain @@ -1141,6 +1154,7 @@ local-zone: "ultimate-24.de" always_nxdomain local-zone: "umwelt-kirchhof.de" always_nxdomain local-zone: "unicorpbrunei.com" always_nxdomain local-zone: "uniengrisb.com" always_nxdomain +local-zone: "unisoftcc.com" always_nxdomain local-zone: "unyazitelecom.com" always_nxdomain local-zone: "upcbpta.com" always_nxdomain local-zone: "urbantrapfest.cl" always_nxdomain @@ -1155,7 +1169,9 @@ local-zone: "vbcargo.hu" always_nxdomain local-zone: "vcah.co.uk" always_nxdomain local-zone: "vectarts.com" always_nxdomain local-zone: "vegadelcasero.cl" always_nxdomain +local-zone: "velma-harber30ku.com" always_nxdomain local-zone: "vendas.lidiacarmeli.com.br" always_nxdomain +local-zone: "versualstudio.com" always_nxdomain local-zone: "veterinariadrpopui.com" always_nxdomain local-zone: "vfocus.net" always_nxdomain local-zone: "vienen.gblix.srv.br" always_nxdomain @@ -1182,6 +1198,7 @@ local-zone: "vvsskmodinationalschool.com" always_nxdomain local-zone: "w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu" always_nxdomain local-zone: "wanepliberia.org" always_nxdomain local-zone: "wanepniger.org" always_nxdomain +local-zone: "weareactum.com" always_nxdomain local-zone: "web.eng.ubu.ac.th" always_nxdomain local-zone: "web.geetle.ga" always_nxdomain local-zone: "web.geomegasoft.net" always_nxdomain @@ -1209,6 +1226,7 @@ local-zone: "wolfgang-brodte.de" always_nxdomain local-zone: "wonderhawaii.com" always_nxdomain local-zone: "woodsytech.com" always_nxdomain local-zone: "wordpress.saleensuporte.com.br" always_nxdomain +local-zone: "workingsolutionsrome.org" always_nxdomain local-zone: "wozata.000webhostapp.com" always_nxdomain local-zone: "wp.readhere.in" always_nxdomain local-zone: "wpdemo.101clients.com.au" always_nxdomain @@ -1230,7 +1248,6 @@ local-zone: "yoast.yourpageserver.com" always_nxdomain local-zone: "yourclub1.com" always_nxdomain local-zone: "yourtopdog.com.au" always_nxdomain local-zone: "youtubetrainingacademy.com" always_nxdomain -local-zone: "yp.hnggzyjy.cn" always_nxdomain local-zone: "yskadvisors.com" always_nxdomain local-zone: "yummyyogaudaipur.com" always_nxdomain local-zone: "yzkzixun.com" always_nxdomain diff --git a/urlhaus-filter-unbound.conf b/urlhaus-filter-unbound.conf index 322da266..afb06367 100644 --- a/urlhaus-filter-unbound.conf +++ b/urlhaus-filter-unbound.conf @@ -1,5 +1,5 @@ # Title: Malicious Domains Unbound Blocklist -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -238,7 +238,6 @@ local-zone: "123mobile.store" always_nxdomain local-zone: "123moviesfx.com" always_nxdomain local-zone: "123sellfast.com" always_nxdomain local-zone: "123sex.co" always_nxdomain -local-zone: "123tadi.com" always_nxdomain local-zone: "123xyz.xyz" always_nxdomain local-zone: "124.com.ua" always_nxdomain local-zone: "124.cpanel.realwebsitesite.com" always_nxdomain @@ -7094,7 +7093,6 @@ local-zone: "app.bigplan-alex.com" always_nxdomain local-zone: "app.boxrcdn.com" always_nxdomain local-zone: "app.bridgeimpex.org" always_nxdomain local-zone: "app.calag.at" always_nxdomain -local-zone: "app.casetabs.com" always_nxdomain local-zone: "app.catholicchurch.co.in" always_nxdomain local-zone: "app.choiphui.com" always_nxdomain local-zone: "app.cloudindustry.net" always_nxdomain @@ -11326,6 +11324,7 @@ local-zone: "beanmatrix.com" always_nxdomain local-zone: "beansmedia.com" always_nxdomain local-zone: "beanssur.com" always_nxdomain local-zone: "beantreefoods.com" always_nxdomain +local-zone: "beanx88.xyz" always_nxdomain local-zone: "beanz-network.com" always_nxdomain local-zone: "bearcatpumps.com.cn" always_nxdomain local-zone: "beard-companies.com" always_nxdomain @@ -17627,7 +17626,6 @@ local-zone: "cdncomfortgroup.website" always_nxdomain local-zone: "cdndownloadlp.club" always_nxdomain local-zone: "cdnmultimedia.com" always_nxdomain local-zone: "cdnpic.mgyun.com" always_nxdomain -local-zone: "cdnrep.reimageplus.com" always_nxdomain local-zone: "cdnxh.net" always_nxdomain local-zone: "cdoconsult.com.br" always_nxdomain local-zone: "cdolechon.com" always_nxdomain @@ -18370,7 +18368,6 @@ local-zone: "cheapesthost.com.ng" always_nxdomain local-zone: "cheapgadgets-gq.000webhostapp.com" always_nxdomain local-zone: "cheapistan.pk" always_nxdomain local-zone: "cheapmlbjerseysmarlins.com" always_nxdomain -local-zone: "cheapmusic.info" always_nxdomain local-zone: "cheapoakleysunglasses.net" always_nxdomain local-zone: "cheappigeontraps.com" always_nxdomain local-zone: "cheapraccoontraps.com" always_nxdomain @@ -18419,7 +18416,6 @@ local-zone: "cheekie2.neagoeandrei.com" always_nxdomain local-zone: "cheematransxpressinc.com" always_nxdomain local-zone: "cheerchile.cl" always_nxdomain local-zone: "cheerfulgiversneverlack.com" always_nxdomain -local-zone: "cheerfullydo.com" always_nxdomain local-zone: "cheesecakery.com.br" always_nxdomain local-zone: "cheetahridge.mediadevstaging.com" always_nxdomain local-zone: "chef-solutions.dreamscape.co.in" always_nxdomain @@ -18858,6 +18854,7 @@ local-zone: "christina.makeyourselfelaborate.com" always_nxdomain local-zone: "christinablunsum.com" always_nxdomain local-zone: "christinailoveyousomuchyoumyheart.duckdns.org" always_nxdomain local-zone: "christinalenway.com" always_nxdomain +local-zone: "christinekeller.ch" always_nxdomain local-zone: "christinelebeck.com" always_nxdomain local-zone: "christinmunsch.com" always_nxdomain local-zone: "christmasatredeemer.org" always_nxdomain @@ -24428,6 +24425,7 @@ local-zone: "demo.jjmayurved.com" always_nxdomain local-zone: "demo.jrkcompany.com" always_nxdomain local-zone: "demo.kalapifoods.com" always_nxdomain local-zone: "demo.kanapebudapest.hu" always_nxdomain +local-zone: "demo.kechuahangdidong.com" always_nxdomain local-zone: "demo.kzonetechnologies.com" always_nxdomain local-zone: "demo.lamppostmedia.in" always_nxdomain local-zone: "demo.lapizblanco.com" always_nxdomain @@ -26492,7 +26490,6 @@ local-zone: "dl-45538429.onedrives-en-live.com" always_nxdomain local-zone: "dl-675423.store-downloads.com" always_nxdomain local-zone: "dl-80076342.md-downloads.com" always_nxdomain local-zone: "dl-97674424.md-downloads.com" always_nxdomain -local-zone: "dl-gameplayer.dmm.com" always_nxdomain local-zone: "dl-link.link" always_nxdomain local-zone: "dl-link.live" always_nxdomain local-zone: "dl-link.network" always_nxdomain @@ -26523,7 +26520,6 @@ local-zone: "dl.repairlabshost.com" always_nxdomain local-zone: "dl.rina-roleplay.com" always_nxdomain local-zone: "dl.river-store.com" always_nxdomain local-zone: "dl.rp-soft.ir" always_nxdomain -local-zone: "dl.softservers.net" always_nxdomain local-zone: "dl.svcupdate.com" always_nxdomain local-zone: "dl.teeqee.com" always_nxdomain local-zone: "dl.x420.me" always_nxdomain @@ -27326,8 +27322,10 @@ local-zone: "down.pcclear.com" always_nxdomain local-zone: "down.post-gg.top" always_nxdomain local-zone: "down.postch-b.top" always_nxdomain local-zone: "down.postch-bsw.top" always_nxdomain +local-zone: "down.postch-de.top" always_nxdomain local-zone: "down.postch-dfa.top" always_nxdomain local-zone: "down.postch-dj.top" always_nxdomain +local-zone: "down.postch-dl.top" always_nxdomain local-zone: "down.postch-fa.top" always_nxdomain local-zone: "down.postch-fj.top" always_nxdomain local-zone: "down.postch-kf.top" always_nxdomain @@ -29138,7 +29136,6 @@ local-zone: "economiadeltempo.it" always_nxdomain local-zone: "economiadigital.biz" always_nxdomain local-zone: "economika.com.ve" always_nxdomain local-zone: "economizei.shop" always_nxdomain -local-zone: "economplast.com" always_nxdomain local-zone: "economywindowcleaner.com" always_nxdomain local-zone: "econoteen.fea.usp.br" always_nxdomain local-zone: "econotel.us" always_nxdomain @@ -33847,7 +33844,6 @@ local-zone: "files.danwin1210.me" always_nxdomain local-zone: "files.dropmybin.me" always_nxdomain local-zone: "files.enjin.com" always_nxdomain local-zone: "files.gathercdn.com" always_nxdomain -local-zone: "files.hrloo.com" always_nxdomain local-zone: "files.l-d.tech" always_nxdomain local-zone: "files.martellexpress.us" always_nxdomain local-zone: "files.mirai-2viv.vn" always_nxdomain @@ -36060,6 +36056,7 @@ local-zone: "fuzzymiles.com" always_nxdomain local-zone: "fv1-2.failiem.lv" always_nxdomain local-zone: "fv13.failiem.lv" always_nxdomain local-zone: "fv15.failiem.lv" always_nxdomain +local-zone: "fv2-2.failiem.lv" always_nxdomain local-zone: "fv2-7.failiem.lv" always_nxdomain local-zone: "fv3.failiem.lv" always_nxdomain local-zone: "fv6.failiem.lv" always_nxdomain @@ -40303,7 +40300,6 @@ local-zone: "hangtotma.com" always_nxdomain local-zone: "hangtrentroi.com" always_nxdomain local-zone: "hangulcafes.ga" always_nxdomain local-zone: "hanh.cz" always_nxdomain -local-zone: "hanhtrinhtamlinh.com" always_nxdomain local-zone: "hanhtrinhthanhnienkhoinghiep.vn" always_nxdomain local-zone: "haniamarket.com" always_nxdomain local-zone: "hanict.org.vn" always_nxdomain @@ -40498,7 +40494,6 @@ local-zone: "harrisburgprinting.com" always_nxdomain local-zone: "harriscustomcatering.com" always_nxdomain local-zone: "harrisheatpumps.nz" always_nxdomain local-zone: "harrisnewtech.ir" always_nxdomain -local-zone: "harrisoncarter.com" always_nxdomain local-zone: "harrisonlily.co.uk" always_nxdomain local-zone: "harryfang.com" always_nxdomain local-zone: "harryhiggins.com" always_nxdomain @@ -43299,7 +43294,6 @@ local-zone: "i-sharecloud.com" always_nxdomain local-zone: "i-supportcharity.com" always_nxdomain local-zone: "i-vnsweyu.pl" always_nxdomain local-zone: "i-voda.com" always_nxdomain -local-zone: "i.fiery.me" always_nxdomain local-zone: "i.fluffy.cc" always_nxdomain local-zone: "i.funtourspt.eu" always_nxdomain local-zone: "i.ooxx.ooo" always_nxdomain @@ -49680,6 +49674,7 @@ local-zone: "kebunrayabaturraden.id" always_nxdomain local-zone: "kec-cendana.enrekangkab.go.id" always_nxdomain local-zone: "kec-wlingi.blitarkab.go.id" always_nxdomain local-zone: "kecforging.com" always_nxdomain +local-zone: "kechuahangdidong.com" always_nxdomain local-zone: "keciorenkoltukyikama.net" always_nxdomain local-zone: "keckarangdadap.pekalongankab.go.id" always_nxdomain local-zone: "kecsfila.hu" always_nxdomain @@ -67483,6 +67478,7 @@ local-zone: "osrsport.com" always_nxdomain local-zone: "ossandonycia.cl" always_nxdomain local-zone: "osscaar.com" always_nxdomain local-zone: "osservatore.betacom.it" always_nxdomain +local-zone: "ossi4.51cto.com" always_nxdomain local-zone: "ossianlaw.com" always_nxdomain local-zone: "osslusturv.com" always_nxdomain local-zone: "ossoriobouliz.com" always_nxdomain @@ -70815,6 +70811,7 @@ local-zone: "politinsky.000webhostapp.com" always_nxdomain local-zone: "politrix.net" always_nxdomain local-zone: "poliyzsl.host" always_nxdomain local-zone: "poljimenez.com" always_nxdomain +local-zone: "polk.k12.ga.us" always_nxdomain local-zone: "polka32.ru" always_nxdomain local-zone: "polkapower.com" always_nxdomain local-zone: "polkolonieb4k.pl" always_nxdomain @@ -71986,7 +71983,6 @@ local-zone: "professionalshop.in" always_nxdomain local-zone: "professionalwaiterskollege.org" always_nxdomain local-zone: "professionelelit.com" always_nxdomain local-zone: "professorsgallery.com" always_nxdomain -local-zone: "profetestruec.net" always_nxdomain local-zone: "profexsystem.com" always_nxdomain local-zone: "proffessia.ru" always_nxdomain local-zone: "proffice.com.pl" always_nxdomain @@ -72364,6 +72360,7 @@ local-zone: "protech.binarybizz.com" always_nxdomain local-zone: "protech.mn" always_nxdomain local-zone: "protechcarpetcare.com" always_nxdomain local-zone: "protechgroup1.com" always_nxdomain +local-zone: "protect.mimecast-offshore.com" always_nxdomain local-zone: "protectiadatelor.biz" always_nxdomain local-zone: "protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org" always_nxdomain local-zone: "protection.pecol.eu" always_nxdomain @@ -80470,7 +80467,6 @@ local-zone: "shareallfilesthroughsecureexchangesystem.duckdns.org" always_nxdoma local-zone: "sharebook.tk" always_nxdomain local-zone: "sharechautari.com" always_nxdomain local-zone: "shared-cnd.com" always_nxdomain -local-zone: "shared.pdffiller.com" always_nxdomain local-zone: "shareddocuments.ml" always_nxdomain local-zone: "shareddynamics.com" always_nxdomain local-zone: "sharedeconomy.eu" always_nxdomain @@ -86099,6 +86095,7 @@ local-zone: "sup3rc10ud.ga" always_nxdomain local-zone: "supadom.fr" always_nxdomain local-zone: "supamidland-my.sharepoint.com" always_nxdomain local-zone: "supcargo.com" always_nxdomain +local-zone: "supdate.mediaweb.co.kr" always_nxdomain local-zone: "super-filtr.ru" always_nxdomain local-zone: "super-gamezer.com" always_nxdomain local-zone: "super-industries.co" always_nxdomain @@ -90717,7 +90714,6 @@ local-zone: "tlcmoto.com" always_nxdomain local-zone: "tldrbox.top" always_nxdomain local-zone: "tlextreme.com" always_nxdomain local-zone: "tlfthelifefactory.com.au" always_nxdomain -local-zone: "tlgur.com" always_nxdomain local-zone: "tlkcloudem.com" always_nxdomain local-zone: "tlktdsfj.sha58.me" always_nxdomain local-zone: "tlpclient.site" always_nxdomain @@ -92353,6 +92349,7 @@ local-zone: "tsport88.com" always_nxdomain local-zone: "tsr-mark.xyz" always_nxdomain local-zone: "tsredco.telangana.gov.in" always_nxdomain local-zone: "tsrj.monster" always_nxdomain +local-zone: "tsrv2.top" always_nxdomain local-zone: "tst.marineindust.com" always_nxdomain local-zone: "tstfrigo.com" always_nxdomain local-zone: "tsugite.youbi.me" always_nxdomain @@ -93764,6 +93761,7 @@ local-zone: "update-chase.justmoveup.com" always_nxdomain local-zone: "update-prog.com" always_nxdomain local-zone: "update-res.100public.com" always_nxdomain local-zone: "update.5v.pl" always_nxdomain +local-zone: "update.7h4uk.com" always_nxdomain local-zone: "update.att.tools" always_nxdomain local-zone: "update.bracncet.net" always_nxdomain local-zone: "update.bruss.org.ru" always_nxdomain @@ -94003,6 +94001,7 @@ local-zone: "url-update.com" always_nxdomain local-zone: "url-validation-clients.com" always_nxdomain local-zone: "url.246546.com" always_nxdomain local-zone: "url.57569.fr.snd52.ch" always_nxdomain +local-zone: "url2.mailanyone.net" always_nxdomain local-zone: "url3.mailanyone.net" always_nxdomain local-zone: "url5459.41southbar.com" always_nxdomain local-zone: "url675.textilmallorca.com" always_nxdomain @@ -95401,7 +95400,6 @@ local-zone: "viettrungkhaison.com" always_nxdomain local-zone: "viettrust-vn.net" always_nxdomain local-zone: "vietucgroup.org" always_nxdomain local-zone: "vietup.net" always_nxdomain -local-zone: "vietvictory.vn" always_nxdomain local-zone: "vievioparapija.eu" always_nxdomain local-zone: "view-indonesia.com" always_nxdomain local-zone: "view-your-website.com" always_nxdomain @@ -95855,6 +95853,7 @@ local-zone: "visual-sounds.com" always_nxdomain local-zone: "visualblends.com" always_nxdomain local-zone: "visualdata.ru" always_nxdomain local-zone: "visualdimensioniq.com" always_nxdomain +local-zone: "visualdive.com" always_nxdomain local-zone: "visualendodontics.net" always_nxdomain local-zone: "visualgag.co.uk" always_nxdomain local-zone: "visualhome.cl" always_nxdomain @@ -96933,7 +96932,6 @@ local-zone: "wc2018.top" always_nxdomain local-zone: "wc3prince.ru" always_nxdomain local-zone: "wcare.nl" always_nxdomain local-zone: "wcbgroup.co.uk" always_nxdomain -local-zone: "wcdownloadercdn.lavasoft.com" always_nxdomain local-zone: "wcdr.pbas.es" always_nxdomain local-zone: "wcf-old.sibcat.info" always_nxdomain local-zone: "wcfamlaw.com" always_nxdomain @@ -98599,6 +98597,7 @@ local-zone: "workingin-my.sharepoint.com" always_nxdomain local-zone: "workingonit.site" always_nxdomain local-zone: "workingpainters.com" always_nxdomain local-zone: "workingroofers.com" always_nxdomain +local-zone: "workingsolutionsrome.org" always_nxdomain local-zone: "workingwell.club" always_nxdomain local-zone: "worklinic.com.br" always_nxdomain local-zone: "workmate-sien.com" always_nxdomain @@ -100965,7 +100964,6 @@ local-zone: "yoyoplease.com" always_nxdomain local-zone: "yoyoso.nz" always_nxdomain local-zone: "yoyoteacher.cn" always_nxdomain local-zone: "yp.dcyazilim.com" always_nxdomain -local-zone: "yp.hnggzyjy.cn" always_nxdomain local-zone: "ypbb.or.id" always_nxdomain local-zone: "ypddf.org" always_nxdomain local-zone: "ypicsdy.cf" always_nxdomain @@ -101914,6 +101912,7 @@ local-zone: "zoovetdv.ru" always_nxdomain local-zone: "zoox.com.br" always_nxdomain local-zone: "zoparo.nl" always_nxdomain local-zone: "zopbxtjiuykhyyp.usa.cc" always_nxdomain +local-zone: "zopro.duckdns.org" always_nxdomain local-zone: "zoracle.com" always_nxdomain local-zone: "zorancreative.com" always_nxdomain local-zone: "zoratech.ro" always_nxdomain diff --git a/urlhaus-filter-vivaldi-online.txt b/urlhaus-filter-vivaldi-online.txt index 30f6a429..f6af3e29 100644 --- a/urlhaus-filter-vivaldi-online.txt +++ b/urlhaus-filter-vivaldi-online.txt @@ -1,5 +1,5 @@ ! Title: Online Malicious URL Blocklist (Vivaldi) -! Updated: Sat, 03 Apr 2021 00:13:46 UTC +! Updated: Sat, 03 Apr 2021 12:12:28 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -7,6 +7,7 @@ ||0-24bpautomentes.hu$document ||0cl.sldov.ru$document ||1.11.234.99$document +||1.186.151.219$document ||1.222.196.60$document ||1.245.4.163$document ||1.246.222.107$document @@ -16,11 +17,9 @@ ||1.246.222.134$document ||1.246.222.138$document ||1.246.222.14$document -||1.246.222.16$document ||1.246.222.165$document ||1.246.222.20$document ||1.246.222.228$document -||1.246.222.232$document ||1.246.222.234$document ||1.246.222.237$document ||1.246.222.245$document @@ -41,6 +40,7 @@ ||1.246.223.103$document ||1.246.223.105$document ||1.246.223.109$document +||1.246.223.126$document ||1.246.223.127$document ||1.246.223.130$document ||1.246.223.146$document @@ -78,12 +78,10 @@ ||101.73.131.78$document ||101.75.157.99$document ||101.75.167.213$document -||101.99.94.15$document ||102.130.115.14$document ||102.141.240.139$document ||103.113.99.79$document ||103.125.218.107$document -||103.136.82.50$document ||103.141.138.118$document ||103.141.138.12$document ||103.146.174.208$document @@ -92,12 +90,11 @@ ||103.217.215.21$document ||103.224.200.146$document ||103.224.200.40$document -||103.227.118.129$document +||103.237.21.36$document ||103.238.228.4$document ||103.240.249.121$document ||103.4.117.26$document ||103.70.160.51$document -||103.79.112.254$document ||103.82.98.170$document ||103.84.240.130$document ||103.91.245.12$document @@ -142,6 +139,7 @@ ||109.124.90.229$document ||109.233.196.232$document ||109.235.7.228$document +||109.248.58.238$document ||109.86.85.253$document ||109.95.200.102$document ||109.95.200.230$document @@ -155,28 +153,27 @@ ||110.228.195.46$document ||110.241.119.168$document ||110.248.124.254$document +||110.248.175.141$document ||110.248.251.194$document ||110.251.10.18$document ||110.253.150.248$document ||110.253.213.198$document +||110.253.51.112$document ||110.255.101.184$document ||110.255.167.147$document ||110.35.145.127$document ||110.35.208.21$document -||110.35.221.77$document ||110.35.223.92$document ||110.35.225.24$document -||110.35.233.147$document ||110.35.235.57$document +||110.35.249.21$document ||110.35.4.2$document ||110fss.net$document -||111.118.111.207$document ||111.118.41.173$document ||111.118.88.61$document ||111.119.245.114$document ||111.125.67.125$document ||111.165.21.195$document -||111.165.248.134$document ||111.166.236.191$document ||111.167.151.156$document ||111.170.85.71$document @@ -193,22 +190,20 @@ ||111.38.103.66$document ||111.38.104.141$document ||111.38.104.15$document -||111.38.106.128$document ||111.38.106.19$document ||111.38.121.222$document ||111.38.121.223$document ||111.38.121.226$document ||111.38.121.228$document ||111.38.26.243$document +||111.38.8.81$document ||111.61.52.53$document ||112.111.108.184$document -||112.111.31.175$document ||112.133.222.151$document ||112.147.92.51$document ||112.159.108.96$document ||112.163.200.217$document ||112.170.124.75$document -||112.170.233.9$document ||112.186.210.211$document ||112.186.96.252$document ||112.187.91.117$document @@ -262,18 +257,15 @@ ||112.247.81.173$document ||112.247.82.122$document ||112.248.148.90$document -||112.248.179.239$document ||112.248.197.164$document ||112.249.109.217$document ||112.249.118.157$document ||112.249.26.129$document ||112.249.79.98$document ||112.250.102.173$document -||112.250.57.99$document ||112.251.218.210$document ||112.252.136.84$document ||112.252.196.17$document -||112.252.212.122$document ||112.252.221.244$document ||112.252.239.103$document ||112.254.208.123$document @@ -309,7 +301,6 @@ ||112.27.124.177$document ||112.27.124.178$document ||112.27.124.179$document -||112.27.124.71$document ||112.27.127.155$document ||112.27.83.182$document ||112.27.83.23$document @@ -334,7 +325,6 @@ ||112.30.1.91$document ||112.30.110.31$document ||112.30.110.36$document -||112.30.110.37$document ||112.30.110.38$document ||112.30.110.41$document ||112.30.110.43$document @@ -349,21 +339,23 @@ ||112.30.4.136$document ||112.30.4.52$document ||112.31.240.239$document -||112.31.82.160$document ||112.31.87.98$document ||112.53.224.79$document ||112.65.53.175$document +||112.72.153.37$document +||112.72.162.159$document ||112.72.162.49$document ||112.72.162.53$document ||112.72.176.112$document ||112.72.176.84$document -||112.72.231.35$document +||112.72.226.202$document ||112.78.45.158$document ||112.80.117.32$document ||112.80.118.16$document ||112.80.127.91$document ||112.80.207.144$document ||112.80.215.101$document +||112.80.218.56$document ||112.82.146.253$document ||112.82.18.255$document ||112.82.224.139$document @@ -381,16 +373,14 @@ ||113.231.211.131$document ||113.254.169.251$document ||113.59.128.133$document -||113.59.136.39$document +||113.59.133.16$document ||113.59.154.21$document ||113.59.191.47$document ||113.61.204.205$document -||113.87.174.63$document -||113.87.175.135$document -||113.89.42.50$document ||113.89.43.185$document ||113.90.26.136$document -||114.199.204.37$document +||114.111.242.3$document +||114.199.253.235$document ||114.200.154.181$document ||114.224.203.128$document ||114.226.100.56$document @@ -398,31 +388,24 @@ ||114.229.165.194$document ||114.235.115.236$document ||114.30.54.64$document -||114.32.237.100$document ||114.79.172.42$document ||115.165.216.112$document ||115.201.38.185$document ||115.42.47.36$document -||115.48.204.56$document ||115.50.21.56$document ||115.51.125.55$document ||115.52.18.65$document -||115.55.144.42$document -||115.55.145.147$document ||115.55.153.194$document -||115.55.190.144$document ||115.55.60.129$document ||115.56.131.242$document ||115.56.133.96$document ||115.56.144.213$document ||115.56.159.132$document -||115.56.187.173$document ||115.58.132.140$document ||115.58.165.147$document -||115.59.240.217$document ||115.59.255.194$document ||115.61.118.201$document -||115.62.26.39$document +||115.69.102.84$document ||115.73.3.11$document ||115.92.174.231$document ||116.124.219.2$document @@ -431,15 +414,21 @@ ||116.211.100.26$document ||116.212.132.119$document ||116.212.142.215$document -||117.196.49.249$document +||117.194.166.219$document ||117.196.50.107$document ||117.20.204.138$document ||117.20.204.5$document ||117.20.210.52$document +||117.20.220.126$document ||117.20.236.14$document ||117.20.243.40$document +||117.20.247.150$document ||117.200.76.54$document -||117.26.110.103$document +||117.202.66.15$document +||117.202.69.113$document +||117.213.10.108$document +||117.213.15.72$document +||117.248.63.12$document ||117.63.113.146$document ||117.63.195.140$document ||117.63.53.15$document @@ -464,12 +453,11 @@ ||118.42.125.246$document ||118.43.180.33$document ||118.79.125.92$document -||118.79.218.157$document ||118.79.50.203$document ||118.79.58.82$document -||118.79.96.11$document ||118.83.79.43$document ||118.91.24.27$document +||118.91.41.135$document ||118.99.179.164$document ||118.99.183.235$document ||118.99.239.217$document @@ -480,7 +468,6 @@ ||119.147.213.57$document ||119.163.93.191$document ||119.164.18.235$document -||119.164.218.229$document ||119.165.107.93$document ||119.165.163.220$document ||119.165.174.63$document @@ -493,8 +480,6 @@ ||119.167.26.33$document ||119.177.147.38$document ||119.178.248.123$document -||119.179.157.219$document -||119.179.16.149$document ||119.179.170.212$document ||119.179.43.1$document ||119.179.75.8$document @@ -503,7 +488,6 @@ ||119.180.108.227$document ||119.180.108.79$document ||119.180.33.161$document -||119.180.94.80$document ||119.181.119.21$document ||119.181.124.203$document ||119.182.97.232$document @@ -523,12 +507,12 @@ ||119.251.105.221$document ||119.251.14.251$document ||119.56.131.155$document +||119.56.140.73$document ||119.56.143.46$document ||119.56.143.71$document ||119.56.144.75$document ||119.56.148.115$document ||119.56.155.57$document -||119.56.172.28$document ||119.56.175.41$document ||119.56.195.90$document ||119.56.206.43$document @@ -559,22 +543,17 @@ ||120.193.91.212$document ||120.193.91.215$document ||120.193.91.233$document -||120.209.121.243$document ||120.209.126.206$document ||120.209.126.240$document ||120.209.127.187$document ||120.209.99.127$document ||120.210.89.79$document ||120.43.33.202$document -||120.5.15.95$document ||120.50.66.60$document ||120.50.93.115$document -||120.6.141.142$document ||120.6.8.11$document ||120.7.75.99$document ||120.85.173.168$document -||120.85.174.3$document -||120.85.210.232$document ||121.100.114.164$document ||121.100.96.8$document ||121.121.44.222$document @@ -595,10 +574,8 @@ ||121.237.226.202$document ||121.239.15.74$document ||121.24.116.173$document -||121.25.101.86$document ||121.254.43.215$document ||121.254.76.17$document -||121.61.101.125$document ||121.61.98.151$document ||121.88.99.236$document ||122.100.150.204$document @@ -609,7 +586,6 @@ ||122.199.66.28$document ||122.199.72.23$document ||122.199.79.27$document -||122.199.83.86$document ||122.202.37.85$document ||122.202.41.23$document ||122.254.29.37$document @@ -626,28 +602,26 @@ ||123.128.133.91$document ||123.129.84.36$document ||123.130.208.52$document -||123.130.23.110$document ||123.130.27.19$document ||123.130.37.182$document -||123.130.61.210$document -||123.130.77.225$document ||123.131.186.250$document ||123.132.219.147$document ||123.133.125.77$document ||123.133.98.135$document ||123.134.14.130$document ||123.134.50.186$document -||123.14.120.130$document ||123.14.199.130$document +||123.14.248.210$document ||123.153.80.178$document ||123.154.116.116$document ||123.154.236.114$document ||123.154.94.1$document ||123.156.136.21$document +||123.159.68.119$document ||123.159.8.100$document ||123.183.121.60$document -||123.191.150.147$document ||123.191.164.92$document +||123.191.62.239$document ||123.192.101.163$document ||123.192.194.233$document ||123.193.149.235$document @@ -672,13 +646,10 @@ ||123.241.148.58$document ||123.241.184.124$document ||123.28.217.23$document -||123.5.189.116$document ||123.5.5.242$document -||123.8.184.82$document ||124.119.108.87$document ||124.129.221.150$document ||124.129.76.230$document -||124.130.110.167$document ||124.130.40.31$document ||124.131.104.82$document ||124.131.151.135$document @@ -691,7 +662,6 @@ ||124.153.136.175$document ||124.153.236.6$document ||124.160.126.238$document -||124.163.163.193$document ||124.163.65.64$document ||124.163.72.102$document ||124.165.123.7$document @@ -715,8 +685,6 @@ ||125.40.75.22$document ||125.41.215.9$document ||125.43.53.9$document -||125.45.63.67$document -||125.46.129.159$document ||125.79.200.104$document ||128.116.133.92$document ||130.255.159.133$document @@ -728,10 +696,12 @@ ||139.216.102.151$document ||139.227.46.137$document ||14.102.17.222$document +||14.102.97.204$document ||14.136.80.242$document ||14.138.8.51$document -||14.178.163.235$document +||14.160.34.50$document ||14.189.247.118$document +||14.241.227.216$document ||14.37.222.190$document ||14.45.127.110$document ||14.46.25.17$document @@ -758,23 +728,19 @@ ||153.101.47.145$document ||153.3.152.106$document ||153.34.135.92$document -||153.36.126.35$document ||155.138.134.44$document ||158.101.165.14$document ||158.174.213.128$document -||158.247.195.165$document ||158.51.125.115$document ||159.224.74.112$document ||162.194.28.60$document ||162.209.98.174$document ||163.53.206.228$document ||165.90.16.5$document -||168.205.223.254$document ||170.81.238.178$document ||171.113.36.216$document ||171.113.38.107$document ||171.121.255.10$document -||171.34.112.42$document ||171.34.114.181$document ||171.34.176.217$document ||171.34.179.178$document @@ -784,6 +750,7 @@ ||172.114.244.127$document ||172.245.5.185$document ||172.245.5.190$document +||172.245.79.106$document ||172.245.81.19$document ||172.93.194.114$document ||173.167.85.89$document @@ -810,7 +777,6 @@ ||175.169.13.182$document ||175.201.104.192$document ||175.208.230.8$document -||175.212.6.169$document ||175.42.46.118$document ||175.9.24.110$document ||175.9.90.89$document @@ -822,7 +788,6 @@ ||176.111.174.67$document ||176.113.161.104$document ||176.113.161.113$document -||176.113.161.138$document ||176.113.161.60$document ||176.113.161.65$document ||176.113.161.66$document @@ -836,7 +801,7 @@ ||176.123.7.127$document ||176.123.9.243$document ||176.124.7.225$document -||176.221.242.166$document +||176.221.188.251$document ||176.240.84.106$document ||177.11.92.78$document ||177.131.226.235$document @@ -846,35 +811,31 @@ ||178.124.182.187$document ||178.141.142.15$document ||178.150.174.65$document +||178.151.143.2$document ||178.165.122.141$document ||178.175.0.200$document ||178.175.1.137$document -||178.175.1.153$document ||178.175.1.179$document ||178.175.1.248$document ||178.175.1.249$document ||178.175.1.250$document ||178.175.1.44$document ||178.175.1.80$document +||178.175.100.151$document +||178.175.100.7$document ||178.175.101.110$document ||178.175.101.232$document -||178.175.102.133$document ||178.175.102.171$document ||178.175.102.67$document ||178.175.103.98$document -||178.175.104.145$document ||178.175.104.155$document ||178.175.104.69$document -||178.175.105.125$document ||178.175.105.95$document -||178.175.106.118$document ||178.175.106.193$document -||178.175.106.201$document ||178.175.107.0$document ||178.175.107.245$document ||178.175.107.83$document ||178.175.108.105$document -||178.175.108.149$document ||178.175.108.87$document ||178.175.109.129$document ||178.175.109.26$document @@ -886,23 +847,19 @@ ||178.175.111.206$document ||178.175.112.135$document ||178.175.112.139$document +||178.175.112.140$document ||178.175.112.147$document ||178.175.112.159$document ||178.175.112.46$document ||178.175.112.58$document -||178.175.113.27$document ||178.175.114.114$document -||178.175.114.63$document ||178.175.115.110$document ||178.175.115.209$document ||178.175.116.101$document ||178.175.116.138$document -||178.175.116.168$document -||178.175.116.90$document ||178.175.117.30$document ||178.175.118.112$document ||178.175.118.146$document -||178.175.118.210$document ||178.175.119.102$document ||178.175.119.114$document ||178.175.119.69$document @@ -923,18 +880,15 @@ ||178.175.123.248$document ||178.175.123.26$document ||178.175.123.30$document -||178.175.123.48$document ||178.175.123.91$document ||178.175.124.131$document ||178.175.124.155$document ||178.175.124.4$document -||178.175.124.79$document ||178.175.125.14$document ||178.175.125.160$document ||178.175.125.220$document ||178.175.125.88$document ||178.175.126.129$document -||178.175.126.153$document ||178.175.126.252$document ||178.175.126.46$document ||178.175.127.202$document @@ -944,7 +898,6 @@ ||178.175.13.254$document ||178.175.15.199$document ||178.175.15.215$document -||178.175.15.35$document ||178.175.16.108$document ||178.175.16.116$document ||178.175.16.251$document @@ -953,20 +906,17 @@ ||178.175.17.118$document ||178.175.17.61$document ||178.175.18.23$document +||178.175.18.37$document ||178.175.18.75$document ||178.175.19.163$document ||178.175.19.174$document ||178.175.19.91$document -||178.175.2.118$document -||178.175.2.123$document ||178.175.2.209$document ||178.175.2.5$document ||178.175.20.117$document ||178.175.20.70$document ||178.175.20.97$document ||178.175.21.149$document -||178.175.21.184$document -||178.175.21.238$document ||178.175.22.237$document ||178.175.23.144$document ||178.175.23.176$document @@ -978,7 +928,6 @@ ||178.175.25.56$document ||178.175.26.215$document ||178.175.27.114$document -||178.175.27.127$document ||178.175.27.171$document ||178.175.27.213$document ||178.175.27.32$document @@ -986,18 +935,17 @@ ||178.175.27.46$document ||178.175.28.239$document ||178.175.28.47$document -||178.175.29.2$document ||178.175.29.21$document ||178.175.3.172$document ||178.175.3.214$document ||178.175.30.133$document ||178.175.30.151$document ||178.175.30.213$document -||178.175.31.251$document ||178.175.31.73$document ||178.175.32.146$document ||178.175.32.220$document ||178.175.32.89$document +||178.175.33.162$document ||178.175.33.7$document ||178.175.34.217$document ||178.175.34.247$document @@ -1014,11 +962,12 @@ ||178.175.4.144$document ||178.175.4.72$document ||178.175.40.136$document -||178.175.40.166$document ||178.175.40.228$document ||178.175.42.101$document ||178.175.42.6$document ||178.175.43.121$document +||178.175.43.223$document +||178.175.43.229$document ||178.175.43.238$document ||178.175.43.244$document ||178.175.44.0$document @@ -1031,13 +980,11 @@ ||178.175.45.26$document ||178.175.46.129$document ||178.175.46.137$document -||178.175.46.243$document ||178.175.46.41$document ||178.175.46.42$document ||178.175.46.8$document ||178.175.47.143$document ||178.175.48.51$document -||178.175.49.12$document ||178.175.5.57$document ||178.175.50.10$document ||178.175.50.177$document @@ -1056,10 +1003,8 @@ ||178.175.56.82$document ||178.175.56.87$document ||178.175.57.134$document -||178.175.57.179$document ||178.175.58.183$document ||178.175.58.79$document -||178.175.59.131$document ||178.175.59.33$document ||178.175.6.115$document ||178.175.6.140$document @@ -1071,15 +1016,12 @@ ||178.175.60.209$document ||178.175.60.212$document ||178.175.60.221$document -||178.175.61.235$document -||178.175.62.232$document ||178.175.62.70$document ||178.175.62.81$document ||178.175.63.21$document ||178.175.64.156$document ||178.175.66.186$document ||178.175.66.192$document -||178.175.66.211$document ||178.175.68.116$document ||178.175.68.123$document ||178.175.68.209$document @@ -1088,60 +1030,51 @@ ||178.175.69.153$document ||178.175.69.67$document ||178.175.7.105$document -||178.175.7.107$document ||178.175.7.14$document -||178.175.7.21$document ||178.175.7.35$document ||178.175.7.60$document ||178.175.7.79$document -||178.175.70.212$document ||178.175.70.218$document +||178.175.71.179$document ||178.175.72.222$document ||178.175.72.65$document -||178.175.73.42$document ||178.175.75.181$document ||178.175.75.244$document -||178.175.77.248$document -||178.175.77.46$document ||178.175.77.47$document ||178.175.78.169$document ||178.175.78.2$document -||178.175.8.181$document +||178.175.78.242$document ||178.175.80.89$document -||178.175.81.176$document ||178.175.81.226$document -||178.175.81.235$document ||178.175.81.31$document ||178.175.83.2$document +||178.175.83.247$document ||178.175.84.215$document -||178.175.84.61$document ||178.175.85.23$document ||178.175.85.53$document ||178.175.86.59$document ||178.175.87.146$document ||178.175.87.42$document ||178.175.87.91$document -||178.175.88.166$document ||178.175.88.4$document +||178.175.89.121$document ||178.175.89.217$document ||178.175.89.6$document ||178.175.9.179$document ||178.175.9.198$document ||178.175.9.4$document -||178.175.90.81$document +||178.175.90.4$document ||178.175.92.1$document ||178.175.92.102$document ||178.175.92.92$document ||178.175.93.143$document -||178.175.94.182$document ||178.175.94.27$document ||178.175.94.32$document ||178.175.94.40$document ||178.175.94.61$document ||178.175.95.120$document -||178.175.96.218$document ||178.175.96.251$document -||178.175.97.14$document +||178.175.97.113$document ||178.175.98.83$document ||178.175.99.120$document ||178.175.99.130$document @@ -1154,7 +1087,6 @@ ||178.222.252.130$document ||178.34.183.30$document ||178.48.235.59$document -||178.72.91.172$document ||178.95.136.35$document ||179.159.58.134$document ||179.60.84.7$document @@ -1163,7 +1095,6 @@ ||180.116.203.220$document ||180.122.13.227$document ||180.123.208.250$document -||180.125.44.194$document ||180.157.66.204$document ||180.175.236.209$document ||180.176.105.41$document @@ -1199,30 +1130,20 @@ ||182.116.61.252$document ||182.116.99.150$document ||182.117.43.185$document -||182.117.43.82$document ||182.119.120.8$document ||182.119.164.128$document -||182.119.200.62$document ||182.119.202.130$document ||182.120.16.22$document ||182.120.16.46$document -||182.121.127.106$document -||182.123.205.157$document -||182.123.211.239$document -||182.124.138.54$document -||182.126.121.211$document +||182.121.26.37$document ||182.127.152.3$document ||182.160.98.250$document ||182.233.0.252$document ||182.235.252.31$document ||182.53.197.62$document -||183.105.104.83$document ||183.105.225.154$document ||183.109.169.45$document ||183.128.152.115$document -||183.144.9.97$document -||183.185.112.19$document -||183.83.18.203$document ||183.83.29.191$document ||183.92.207.147$document ||184.164.185.41$document @@ -1249,7 +1170,6 @@ ||185.68.230.207$document ||185.81.157.186$document ||185.82.217.185$document -||185.82.217.213$document ||185.82.219.160$document ||185.82.219.161$document ||185.82.219.219$document @@ -1268,7 +1188,6 @@ ||187.12.10.98$document ||187.188.124.229$document ||187.212.200.162$document -||187.85.244.145$document ||188.10.21.14$document ||188.10.231.246$document ||188.113.81.17$document @@ -1277,6 +1196,8 @@ ||188.143.220.152$document ||188.152.41.141$document ||188.169.178.50$document +||188.169.179.127$document +||188.169.199.59$document ||188.242.242.144$document ||188.81.100.83$document ||188.83.202.25$document @@ -1316,7 +1237,6 @@ ||192.227.185.106$document ||192.227.209.27$document ||192.227.220.55$document -||192.227.223.96$document ||192.227.228.67$document ||192.227.230.74$document ||192.3.152.166$document @@ -1350,7 +1270,6 @@ ||1am.co.nz$document ||2.229.89.119$document ||2.239.22.188$document -||2.249.161.188$document ||2.37.149.230$document ||2.37.203.65$document ||2.45.4.24$document @@ -1362,7 +1281,6 @@ ||2.indexsinas.me:811/86.exe$document ||2.indexsinas.me:811/c64.exe$document ||20.185.42.197$document -||200.104.150.167$document ||200.105.167.98$document ||200.111.189.70$document ||200.194.4.24$document @@ -1373,11 +1291,10 @@ ||201.184.163.170$document ||201.187.102.73$document ||201.200.254.86$document +||201.203.221.20$document ||201.203.27.37$document -||201.205.12.170$document ||202.107.233.41$document ||202.150.176.100$document -||202.166.217.54$document ||202.175.103.10$document ||202.29.95.12$document ||202.4.124.58$document @@ -1390,7 +1307,6 @@ ||203.229.21.56$document ||203.236.190.28$document ||203.238.86.202$document -||203.243.142.132$document ||203.70.166.107$document ||203.77.80.159$document ||203.80.119.166$document @@ -1400,7 +1316,6 @@ ||204.195.116.171$document ||205.185.115.74$document ||205.185.116.94$document -||205.185.123.217$document ||206.248.137.132$document ||206.47.41.166$document ||207.180.228.101$document @@ -1410,8 +1325,8 @@ ||209.141.39.50$document ||209.141.40.190$document ||209.141.40.31$document -||209.141.46.87$document ||210.124.149.19$document +||210.180.17.140$document ||210.216.152.122$document ||210.216.153.142$document ||210.57.234.93$document @@ -1422,7 +1337,6 @@ ||211.116.220.37$document ||211.187.132.204$document ||211.187.75.220$document -||211.200.160.239$document ||211.204.215.157$document ||211.210.66.179$document ||211.210.93.93$document @@ -1440,31 +1354,31 @@ ||212.46.197.114$document ||212.56.197.230$document ||212.8.251.211$document +||212.8.251.227$document ||213.123.206.197$document ||213.135.178.253$document ||213.14.173.117$document ||213.149.182.113$document ||213.149.190.193$document -||213.163.104.12$document ||213.163.104.99$document ||213.163.113.135$document ||213.163.113.20$document ||213.163.113.237$document ||213.163.113.6$document ||213.163.114.165$document +||213.163.114.191$document ||213.163.115.105$document ||213.163.115.11$document ||213.163.115.15$document ||213.163.115.30$document ||213.163.115.71$document -||213.163.116.192$document ||213.163.117.151$document +||213.163.118.10$document ||213.163.118.238$document ||213.163.118.65$document ||213.163.119.236$document -||213.163.126.175$document +||213.163.126.145$document ||213.163.126.7$document -||213.163.127.107$document ||213.163.127.46$document ||213.189.178.163$document ||213.240.218.15$document @@ -1479,32 +1393,26 @@ ||216.183.54.169$document ||216.36.12.98$document ||217.11.75.162$document +||217.127.133.214$document ||218.12.181.110$document ||218.2.40.34$document ||218.234.165.18$document ||218.238.246.3$document -||218.28.160.174$document ||218.35.207.119$document ||218.35.227.133$document ||218.35.68.35$document ||218.35.81.81$document ||218.56.93.129$document -||218.58.92.253$document ||218.59.116.203$document -||218.72.207.116$document ||218.79.103.159$document ||218.93.102.63$document ||218.93.102.75$document ||219.155.102.14$document -||219.155.11.207$document -||219.155.12.85$document -||219.155.26.190$document ||219.155.29.165$document ||219.156.186.18$document ||219.157.139.165$document ||219.157.150.91$document ||219.157.214.235$document -||219.157.50.106$document ||219.241.6.180$document ||219.68.1.148$document ||219.68.1.84$document @@ -1513,19 +1421,17 @@ ||219.68.245.63$document ||219.68.5.140$document ||219.69.71.186$document +||219.70.238.66$document ||219.80.217.209$document ||219.85.145.194$document ||21robo.com$document ||220.118.168.155$document ||220.126.237.74$document ||220.200.22.163$document -||220.247.91.17$document ||220.71.239.115$document -||220.90.159.188$document ||221.1.144.183$document ||221.124.78.15$document -||221.15.113.234$document -||221.157.191.178$document +||221.15.125.69$document ||221.160.136.213$document ||221.202.232.230$document ||221.214.130.147$document @@ -1547,16 +1453,15 @@ ||222.119.65.145$document ||222.132.125.138$document ||222.133.103.120$document -||222.135.67.115$document ||222.135.9.5$document ||222.137.148.192$document ||222.137.211.78$document ||222.138.17.132$document ||222.138.237.155$document ||222.140.17.245$document -||222.162.187.43$document ||222.179.215.189$document ||222.185.116.233$document +||222.186.20.19$document ||222.187.9.178$document ||222.211.72.66$document ||222.236.85.220$document @@ -1607,6 +1512,7 @@ ||27.105.106.201$document ||27.105.152.107$document ||27.116.84.57$document +||27.14.211.219$document ||27.14.81.201$document ||27.141.218.17$document ||27.147.29.52$document @@ -1650,8 +1556,6 @@ ||27.207.155.31$document ||27.207.170.203$document ||27.208.119.27$document -||27.208.152.10$document -||27.208.160.177$document ||27.208.164.18$document ||27.208.237.105$document ||27.208.247.130$document @@ -1661,13 +1565,13 @@ ||27.209.208.122$document ||27.209.231.15$document ||27.210.107.125$document -||27.210.172.245$document ||27.210.234.28$document ||27.210.236.134$document +||27.210.32.122$document ||27.210.44.19$document ||27.210.63.243$document ||27.213.104.201$document -||27.213.109.58$document +||27.213.109.105$document ||27.213.175.208$document ||27.213.255.202$document ||27.213.66.112$document @@ -1677,9 +1581,9 @@ ||27.215.190.172$document ||27.215.212.209$document ||27.215.253.149$document -||27.215.34.242$document ||27.215.71.243$document ||27.215.98.242$document +||27.216.117.54$document ||27.216.128.156$document ||27.216.131.66$document ||27.216.144.66$document @@ -1701,17 +1605,13 @@ ||27.220.85.168$document ||27.221.239.223$document ||27.222.241.223$document -||27.222.249.210$document ||27.222.76.80$document ||27.223.242.164$document ||27.24.28.134$document ||27.35.129.198$document ||27.35.154.13$document -||27.35.16.145$document -||27.35.2.30$document ||27.35.212.124$document ||27.35.58.5$document -||27.41.237.129$document ||27.43.117.98$document ||31.0.98.131$document ||31.11.51.57$document @@ -1738,18 +1638,19 @@ ||32.208.157.193$document ||32792.prolocksmithwinterpark.com$document ||35.184.169.169$document -||36.107.209.10$document ||36.108.231.218$document ||36.248.228.64$document +||36.248.83.98$document ||36.250.203.246$document ||36.251.157.225$document ||36.251.18.18$document ||36.251.51.244$document ||36.255.90.219$document +||36.33.128.58$document ||36.33.160.167$document ||36.34.150.236$document ||36.66.105.159$document -||36.66.111.203$document +||36.66.133.125$document ||36.66.139.36$document ||36.89.18.133$document ||360.lcy2zzx.pw$document @@ -1819,7 +1720,6 @@ ||39.81.70.88$document ||39.83.94.11$document ||39.84.115.152$document -||39.85.54.191$document ||39.85.54.4$document ||39.86.129.233$document ||39.86.170.209$document @@ -1830,10 +1730,10 @@ ||39.88.155.96$document ||39.88.233.131$document ||39.88.67.238$document +||39.88.72.9$document ||39.89.108.109$document ||39.89.145.11$document ||39.89.146.198$document -||39.89.146.36$document ||39.89.63.23$document ||39.90.86.212$document ||40.88.2.151$document @@ -1844,14 +1744,15 @@ ||41.219.185.171$document ||41.226.60.115$document ||41.72.203.82$document -||41.86.18.169$document -||41.86.21.23$document +||41.86.18.133$document ||41.86.21.27$document -||41.86.21.38$document +||41.86.5.197$document ||42.202.101.199$document +||42.228.39.211$document ||42.228.43.161$document ||42.228.65.104$document ||42.230.82.176$document +||42.232.81.179$document ||42.235.180.147$document ||42.239.26.122$document ||42.56.15.227$document @@ -1865,7 +1766,9 @@ ||45.133.1.242$document ||45.133.203.192$document ||45.135.134.228$document +||45.14.149.182$document ||45.14.149.204$document +||45.141.84.182$document ||45.141.84.184$document ||45.144.225.118$document ||45.144.225.135$document @@ -1891,16 +1794,12 @@ ||45.51.104.59$document ||45.6.24.251$document ||45.81.235.31$document -||45.85.90.131$document -||45.85.90.179$document ||45.85.90.203$document ||45.9.148.37$document ||45.92.108.125$document -||45.95.169.153$document ||46.117.42.29$document ||46.172.75.231$document ||46.182.173.246$document -||46.182.173.247$document ||46.20.63.218$document ||46.214.27.4$document ||46.24.130.254$document @@ -1918,6 +1817,7 @@ ||47.16.131.51$document ||47.21.202.98$document ||47.46.231.38$document +||49.119.187.230$document ||49.142.162.113$document ||49.142.87.36$document ||49.143.43.93$document @@ -1932,7 +1832,6 @@ ||49.68.221.252$document ||5.188.62.111$document ||5.2.70.50$document -||5.42.37.74$document ||5.53.146.179$document ||5.79.75.210$document ||5.95.226.154$document @@ -1940,7 +1839,6 @@ ||50.115.174.106$document ||50.121.91.255$document ||50.252.47.29$document -||51.222.56.159$document ||54.36.114.136$document ||54.36.180.122$document ||58.114.246.26$document @@ -1955,16 +1853,15 @@ ||58.218.67.253$document ||58.22.212.107$document ||58.226.129.29$document -||58.229.194.122$document ||58.230.89.42$document ||58.238.42.192$document ||58.240.147.97$document ||58.241.78.55$document -||58.243.123.212$document ||58.243.126.133$document ||58.243.208.225$document -||58.248.118.64$document -||58.249.80.181$document +||58.248.142.227$document +||58.249.79.174$document +||58.249.84.131$document ||58.48.154.143$document ||58.72.165.153$document ||58.72.165.39$document @@ -1973,12 +1870,14 @@ ||59.0.211.161$document ||59.102.168.189$document ||59.151.202.3$document -||59.151.207.150$document ||59.151.214.4$document ||59.151.237.51$document ||59.151.246.125$document ||59.23.114.97$document ||59.58.117.226$document +||59.93.18.144$document +||59.96.37.124$document +||59.97.169.237$document ||60.10.91.242$document ||60.13.61.12$document ||60.164.130.220$document @@ -2003,9 +1902,7 @@ ||60.217.177.196$document ||60.217.86.208$document ||60.223.84.102$document -||60.25.109.240$document ||60.253.15.104$document -||60.253.39.88$document ||60.253.4.72$document ||60.253.51.127$document ||60.253.60.174$document @@ -2015,25 +1912,21 @@ ||60.7.8.43$document ||60.7.99.254$document ||61.164.96.98$document -||61.179.171.60$document ||61.179.91.194$document ||61.247.224.66$document ||61.253.94.230$document -||61.3.149.112$document ||61.41.230.161$document ||61.47.220.169$document ||61.52.103.217$document ||61.52.199.47$document -||61.52.207.10$document ||61.52.30.172$document ||61.52.9.166$document -||61.52.9.62$document ||61.52.99.161$document -||61.53.102.137$document ||61.53.117.237$document -||61.53.220.0$document +||61.53.89.220$document ||61.54.103.56$document ||61.54.64.63$document +||61.54.69.77$document ||61.56.180.67$document ||61.56.181.7$document ||61.57.96.116$document @@ -2134,7 +2027,6 @@ ||74.64.139.223$document ||74.75.165.81$document ||75.127.141.52$document -||75.82.36.220$document ||75.83.102.27$document ||75.99.213.61$document ||76.170.11.82$document @@ -2146,7 +2038,6 @@ ||76.95.12.137$document ||77.111.182.31$document ||77.237.25.210$document -||77.53.144.46$document ||77.71.50.153$document ||77.71.52.220$document ||77.89.203.238$document @@ -2168,6 +2059,7 @@ ||79.130.253.13$document ||79.147.123.48$document ||79.175.42.244$document +||79.21.84.63$document ||79.7.170.58$document ||79.79.58.94$document ||79.8.70.162$document @@ -2181,6 +2073,7 @@ ||81.165.44.109$document ||81.191.40.58$document ||81.213.141.184$document +||81.215.199.29$document ||81.218.187.113$document ||81.218.195.216$document ||81.237.128.200$document @@ -2248,7 +2141,7 @@ ||86.35.43.220$document ||87.172.19.130$document ||87.61.89.40$document -||87du.vip$document +||88.119.171.253$document ||88.2.208.71$document ||88.2.219.179$document ||88.225.222.128$document @@ -2282,6 +2175,7 @@ ||92.114.191.82$document ||92.241.78.114$document ||92.27.246.202$document +||92.54.237.237$document ||92.83.62.139$document ||92.85.18.138$document ||93.159.169.190$document @@ -2309,7 +2203,6 @@ ||95.60.146.134$document ||95.66.196.63$document ||95.9.120.40$document -||95.9.81.85$document ||96.239.73.246$document ||96.47.147.169$document ||97.68.140.254$document @@ -2383,6 +2276,7 @@ ||anantam.net.in$document ||andreelapeyre.com$document ||andremaraisbeleggings.co.za$document +||andreonemaia.com$document ||andres.ac.ug$document ||andres.ug$document ||andreshconcejal.solucioneslink.com$document @@ -2392,7 +2286,6 @@ ||anhung1102.vn$document ||anurontv.com$document ||anysbergbiltong.co.za$document -||apartamentoscitta.com$document ||api-ms.cobainaja.id$document ||api.cstdevs.com$document ||api.quocbao.biz$document @@ -2415,15 +2308,17 @@ ||attach.66rpg.com$document ||atteuqpotentialunlimited.com$document ||augustair.com$document +||aulist.com$document +||automaticrefreshments.com$document ||avadhanagames.com$document ||ayahuascasp.com.br$document ||ayamallah.com$document +||aycconsultoriaempresarial.com$document ||azmeasurement.com$document ||b2b.toptanakaryakit.com.tr$document ||backgrounds.pk$document ||badeggdesign.com$document ||balealgodon.mx$document -||ballina.andrewmaughan.com$document ||bangkok-orchids.com$document ||bangladeshunbound.com$document ||bary.sz4h.com$document @@ -2434,6 +2329,7 @@ ||bcmt.elin.co.za$document ||bcrg.co.za$document ||bdnextrend.xyz$document +||beanx88.xyz$document ||bearcatpumps.com.cn$document ||beautincollagen.rs$document ||bekape.co.id$document @@ -2441,6 +2337,7 @@ ||bespokeweddings.ie$document ||bestcarenepal.com$document ||betone.co.kr$document +||betycopaints.com$document ||beveragesmiami.solucioneslink.com$document ||bhavaniengineering.com$document ||bigmikesupplies.co.za$document @@ -2494,7 +2391,6 @@ ||bitbucket.org/tanake5518/fi/downloads/clientrevers.txt$document ||bitbucket.org/tanake5518/fi/downloads/dcrat.exe$document ||bitbucket.org/tanake5518/fi/downloads/dllservices.exe$document -||bitbucket.org/tanake5518/fi/downloads/dllservices2.exe$document ||bitbucket.org/tanake5518/fi/downloads/exe_morris.mcdermott.exe$document ||bitbucket.org/tanake5518/fi/downloads/hans.txt$document ||bitbucket.org/tanake5518/fi/downloads/hulu.txt$document @@ -2525,7 +2421,6 @@ ||bitbucket.org/tanake5518/fi/downloads/taurjok.txt$document ||bitbucket.org/tanake5518/fi/downloads/taurusbabac.exe$document ||bitbucket.org/tanake5518/fi/downloads/telekiller.exe$document -||bitbucket.org/tanake5518/fi/downloads/updateanddr.txt$document ||bitbucket.org/tanake5518/fi/downloads/updateandr.txt$document ||bitbucket.org/tanake5518/fi/downloads/vhajeja.txt$document ||bitbucket.org/tanake5518/fi/downloads/word.txt$document @@ -2549,6 +2444,7 @@ ||bounces.mi-fs.com$document ||boutiqueofferte.com$document ||bpo.correct.go.th$document +||bradleyinstitute.co.za$document ||brandtrust.com.pk$document ||braunfinancial.com.au$document ||brendanquine.com$document @@ -2608,6 +2504,7 @@ ||childselect.com$document ||chinhdropfile.myvnc.com$document ||chinhdropfile80.myvnc.com$document +||chipmania.it$document ||chiptune.com/razor/rzr-winner_intro.zip$document ||cible-energy.com$document ||cifeer.net$document @@ -2626,10 +2523,9 @@ ||codsambal.com$document ||colempaques.info$document ||colfincas.com/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/$document -||colinde.pricesne.com$document ||colorpak.pl$document +||columbia.aula-web.net$document ||community.reimclub.com$document -||comosairdoburaco.com.br$document ||competancy.indigoconsult.net$document ||conceptimagine.ro$document ||config.cqhbkjzx.com$document @@ -2645,7 +2541,6 @@ ||cpanel.shivay.net$document ||cr-sq.com$document ||craftech.nxtnet.ga$document -||crearechile.cl$document ||creationskateboards.com$document ||crecerco.com$document ||crittersbythebay.com$document @@ -2655,7 +2550,6 @@ ||crscorretordeimoveis.com.br$document ||cse-engineer.com$document ||csnserver.com$document -||ctracknxt.in$document ||cubescargoexpress.com$document ||curasoles.co.za$document ||currantmedia.com$document @@ -2674,7 +2568,6 @@ ||data.over-blog-kiwi.com$document ||datapolish.com$document ||dating.khokhas.co.za$document -||datsom.vn$document ||davethompson.me.uk$document ||davidmcguinness.info$document ||dayspringdaisies.com$document @@ -2699,7 +2592,6 @@ ||detorre.es$document ||dev.sebpo.net$document ||dev.watch-store.eu$document -||dezcom.com$document ||dfcf.91756.cn$document ||dfsfcsfcdsfsdvcfsvcscv.com$document ||diamantenegro.mi-fs.com$document @@ -2714,6 +2606,7 @@ ||dl.packetstormsecurity.net$document ||dl.rina-roleplay.com$document ||dnn.alibuf.com$document +||dns.alibuf.com$document ||dns.cyberium.cc$document ||dockerupdate.anondns.net$document ||docman.orientalservices.in$document @@ -2731,6 +2624,8 @@ ||dosman.pl$document ||dovberger.com$document ||down.pcclear.com$document +||down.postch-de.top$document +||down.postch-dl.top$document ||down.udashi.com$document ||down.webbora.com$document ||down1.arpun.com$document @@ -2761,7 +2656,6 @@ ||drive.google.com/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv$document ||drive.google.com/uc?export=download&id=1cos43rmscrescxk3u40qjuqbwr-pydsn$document ||drive.google.com/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben$document -||drive.google.com/uc?export=download&id=1dhoxtwbb2ycn8q06gi3p-ao_llldff0e$document ||drive.google.com/uc?export=download&id=1dnm3wtjf6ud5fv6zop9cvbr4rs2of1-n$document ||drive.google.com/uc?export=download&id=1dqin1sdd6rbah3sggzsxzeqgrkmhjnqm$document ||drive.google.com/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi$document @@ -2855,7 +2749,6 @@ ||f1sol.com$document ||fahrzeugdrive.com$document ||familydentist.site$document -||faveraprojects.com$document ||fc.co.mz$document ||felicienne.nl$document ||file.elecfans.com/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe$document @@ -2865,7 +2758,7 @@ ||filmotainment.com$document ||final.makkahkmcc.com$document ||fineartgallerym.com$document -||fisconline.casa$document +||fisconline.bar$document ||fix-america-now.org$document ||fixauto.illumetechnology.com$document ||fixturegovernment.com$document @@ -2880,7 +2773,6 @@ ||footweardirect.elin.co.za$document ||forum.mdb.nu$document ||fotoobjetivo.com$document -||foundationrepairhoustontx.net$document ||foxeps.com.br$document ||fraud.bpcbankingtech.com$document ||freecnetdownload.com$document @@ -2889,7 +2781,6 @@ ||fullelectronica.com.ar$document ||funletters.net$document ||fusionfiresolutions.com$document -||futbolpr.com$document ||futuregraphics.com.ar$document ||g.pinmonkey.xyz$document ||gametwogame.com$document @@ -2907,6 +2798,7 @@ ||giadungg7.com$document ||giddos.ga$document ||gist.githubusercontent.com/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe$document +||giteletropical.com$document ||glowinmedia.co.ke$document ||gmsebpl.com$document ||gmtransformationacademy.com$document @@ -2919,6 +2811,7 @@ ||goldcoastoffice365.com.au$document ||golden-memories-funerals.yourpageserver.com$document ||goldenasiacapital.com$document +||goldmen.in$document ||gorecycle.fahadjutt.com$document ||gpotecnosystems.com$document ||gracejukes.com$document @@ -2947,17 +2840,17 @@ ||highlandroadcoc.com$document ||highlandslasvegas.atakdev.com$document ||hindi.factsriver.com$document -||hiptool.net$document ||hitpe.com$document ||hitstation.nl$document +||hlmd.in$document ||hmpmall.co.kr$document ||hoagietesting10.com$document ||hoayeuthuong-my.sharepoint.com$document -||holmesservices.mobiledevsite.co$document ||homefindersolutions.com$document ||hongluosi.com$document ||hookedupboatclub.com$document ||hortizwp.eastus.cloudapp.azure.com$document +||hostingcloud.racing/7991.js$document ||hostingparacolombia.com$document ||hostzaa.com$document ||houstonshutters.site$document @@ -2966,7 +2859,6 @@ ||hrnautica.com.br$document ||hsecaravans.co.uk/wp-admin/suy/$document ||hseda.com$document -||hsmwebapp.com$document ||htownbars.com$document ||hubtech.co.za$document ||huellacero.cl$document @@ -3010,16 +2902,19 @@ ||ipmes.ma$document ||iremart.es$document ||iris101.co.uk$document +||isaac.mikhailmotoringschool.com$document ||iscamenabe.com$document ||isiphephelocon.co.za$document ||iso-dubai.net$document ||israrulhaq.me$document +||isrorg.com$document ||isso.ps$document ||ist-security.com$document ||it123.ru$document ||italiandirezione.casa$document ||itc-demo.softgig.co.ke$document ||itelsys.ma$document +||itmotasaciones.com$document ||jacktech.jackindia.com$document ||jaishritours.com$document ||jamiekaylive.com$document @@ -3034,6 +2929,7 @@ ||jhayesconsulting.com$document ||jiaoyuzixun.cn$document ||jing-da.com.tw$document +||jmtc.91756.cn$document ||jnanbharati.com$document ||jobs.thebeessolution.com$document ||joelbonissilver.com$document @@ -3047,6 +2943,7 @@ ||jupiter.toxsl.in$document ||justinscott.com.au$document ||kadigital.co.uk$document +||kaizenjanitorial.com$document ||kalawatihomes.com$document ||kalogirosfinance.com$document ||kaptaanchapal.com$document @@ -3113,14 +3010,16 @@ ||lp.definerisco.com$document ||lp.difusodesign.com$document ||lp.quama.pe$document -||ltc.typoten.com$document +||luckybrownie.com$document ||luminouspneuma.com$document ||luxomodels.com$document ||m-technics.kz$document ||m.estudiomoros.com.ar$document ||m.mobilelocalsales.com$document +||m.softsharks.com$document ||madicon.co.za$document ||magianegramagiablancayamarres.com$document +||maharaniworld.com$document ||mail.bs-eiendomme.co.za$document ||mail.golimoapp.com$document ||mail.jeffsono.org$document @@ -3133,6 +3032,7 @@ ||mangalyaa.lk$document ||manhtien.net$document ||marcapinyo.ru$document +||marcostrombetta.com.br/ds/1802.gif$document ||mario-sunjic.com$document ||mariobrown.net$document ||mariotessarollo.com$document @@ -3146,7 +3046,6 @@ ||maxiquim.cl$document ||maxoprint.co.uk$document ||maxtox.com.pk$document -||maybethescobar.com$document ||mbgrm.com$document ||mbjtimes.com$document ||mbsolutions.ge$document @@ -3177,12 +3076,13 @@ ||michimal2.000webhostapp.com$document ||microblading.mirliandias.com.br$document ||microcomm-group.com$document +||mikhailmotoringschool.com$document +||mills-skyla30ec.com$document ||mingguanwms.com$document ||minpic.de/k/big5/1giof6/$document ||minuevavida.org$document ||mirror.mypage.sk$document ||misterson.com$document -||mixr.at$document ||mkontakt.az$document ||mktf.mx$document ||mmdx.com$document @@ -3195,7 +3095,9 @@ ||moninediy.com$document ||mopai.sg$document ||moreirawag.ac.ug$document +||morrobaydrugandgift.com/wp-contentbak/t9m/$document ||motorcomunicacion.com$document +||moumitas.com/ds/0204.gif$document ||msacontabil.com.br$document ||mtspsmjeli.sch.id$document ||mumgee.co.za$document @@ -3222,6 +3124,7 @@ ||nec-i.com$document ||nedkellymyanmar.com$document ||nelitrianggraeni.000webhostapp.com$document +||nellaimasthanbiryani.com$document ||nerve.untergrund.net$document ||nettube.com.br$document ||networkwheels.co.za$document @@ -3248,7 +3151,6 @@ ||nobius.org$document ||nocalnoodle.elin.co.za$document ||nomadicbees.com$document -||nonnarina.ax$document ||notamuzikaletleri.com$document ||note.youdao.com/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a$document ||ns1.the-widyantos.com$document @@ -3270,6 +3172,7 @@ ||omega.az$document ||oms.pappai.com$document ||omscoc.pappai.com$document +||onedigitalcard.granvizionnecorp.com$document ||onedrive.listifyapp.co$document ||onedrive.live.com/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12!107&authkey=aajf_ov-e9w3tyq$document ||onedrive.live.com/download?%20%20cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21107&authkey=aajf_ov-e9w3tyq$document @@ -3295,8 +3198,6 @@ ||onedrive.live.com/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq$document ||onedrive.live.com/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko$document ||onedrive.live.com/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw$document -||onedrive.live.com/download?cid=032ce380af7ab389&resid=32ce380af7ab389!210&authkey=akcynbtc0h3ui7e$document -||onedrive.live.com/download?cid=032ce380af7ab389&resid=32ce380af7ab389%21210&authkey=akcynbtc0h3ui7e$document ||onedrive.live.com/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma$document ||onedrive.live.com/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48$document ||onedrive.live.com/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq$document @@ -3331,12 +3232,15 @@ ||onedrive.live.com/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4$document ||onedrive.live.com/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve$document ||onedrive.live.com/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w$document +||onedrive.live.com/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a$document ||onedrive.live.com/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a$document ||onedrive.live.com/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg$document ||onedrive.live.com/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60$document ||onedrive.live.com/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg$document ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4$document ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c$document +||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0$document +||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc$document ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c$document ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!140&authkey=apn44x6bxlzq3ac$document ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!151&authkey=aeuk7knodrpenek$document @@ -3346,30 +3250,20 @@ ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs$document ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0$document ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd$document -||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc$document ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c$document ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21140&authkey=apn44x6bxlzq3ac$document ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21151&authkey=aeuk7knodrpenek$document ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21153&authkey=ao6e8g0bzbp_idw$document ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21154&authkey=ah4chedbotzpmtq$document ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21156&authkey=ajnqscnmrdonpkg$document -||onedrive.live.com/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po$document ||onedrive.live.com/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe$document ||onedrive.live.com/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk$document ||onedrive.live.com/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca$document -||onedrive.live.com/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca$document ||onedrive.live.com/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu$document ||onedrive.live.com/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k$document ||onedrive.live.com/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo$document -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk$document -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei$document -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte$document -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk$document -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei$document -||onedrive.live.com/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte$document ||onedrive.live.com/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga$document ||onedrive.live.com/download?cid=2968c371f5450503&resid=2968c371f5450503!122&authkey=aaqhhxbnwfwrz28$document -||onedrive.live.com/download?cid=2968c371f5450503&resid=2968c371f5450503%21122&authkey=aaqhhxbnwfwrz28$document ||onedrive.live.com/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0$document ||onedrive.live.com/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620$document ||onedrive.live.com/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo$document @@ -3394,7 +3288,6 @@ ||onedrive.live.com/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8$document ||onedrive.live.com/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc$document ||onedrive.live.com/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0$document -||onedrive.live.com/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8$document ||onedrive.live.com/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus$document ||onedrive.live.com/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa$document ||onedrive.live.com/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa$document @@ -3413,7 +3306,6 @@ ||onedrive.live.com/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog$document ||onedrive.live.com/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog$document ||onedrive.live.com/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky$document -||onedrive.live.com/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky$document ||onedrive.live.com/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba!2203&authkey=ajvalmr5l8epwvm$document ||onedrive.live.com/download?cid=41efd5666d65e6ba&resid=41efd5666d65e6ba%212203&authkey=ajvalmr5l8epwvm$document ||onedrive.live.com/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm$document @@ -3439,7 +3331,6 @@ ||onedrive.live.com/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc$document ||onedrive.live.com/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y$document ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8$document -||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0$document ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc$document ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs$document ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts$document @@ -3449,9 +3340,11 @@ ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday$document ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0$document ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas$document +||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve$document ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy$document ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14$document ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i$document +||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa$document ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu$document ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c$document ||onedrive.live.com/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy$document @@ -3478,9 +3371,11 @@ ||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so$document ||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq$document ||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s$document +||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww$document ||onedrive.live.com/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8$document ||onedrive.live.com/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4$document ||onedrive.live.com/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu$document +||onedrive.live.com/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi$document ||onedrive.live.com/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8$document ||onedrive.live.com/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8$document ||onedrive.live.com/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2$document @@ -3489,6 +3384,7 @@ ||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8$document ||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq$document ||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8$document +||onedrive.live.com/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq$document ||onedrive.live.com/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g$document ||onedrive.live.com/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum$document ||onedrive.live.com/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi$document @@ -3503,11 +3399,11 @@ ||onedrive.live.com/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki$document ||onedrive.live.com/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s$document ||onedrive.live.com/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki$document -||onedrive.live.com/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s$document ||onedrive.live.com/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc$document ||onedrive.live.com/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc$document ||onedrive.live.com/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo$document ||onedrive.live.com/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva$document +||onedrive.live.com/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc$document ||onedrive.live.com/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles$document ||onedrive.live.com/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg$document ||onedrive.live.com/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai$document @@ -3531,11 +3427,9 @@ ||onedrive.live.com/download?cid=65b95c6d9d5c3b12&resid=65b95c6d9d5c3b12%21109&authkey=ap-okubj9bvtlc0$document ||onedrive.live.com/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi$document ||onedrive.live.com/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e$document -||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90$document ||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c$document ||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90$document ||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c$document -||onedrive.live.com/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk$document ||onedrive.live.com/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4$document ||onedrive.live.com/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo$document ||onedrive.live.com/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2!517&authkey=akfewcyiwlwomyk$document @@ -3566,7 +3460,6 @@ ||onedrive.live.com/download?cid=7043c80efc0bdbd6&resid=7043c80efc0bdbd6%21305&authkey=an-uuhplpk2zp5u$document ||onedrive.live.com/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu$document ||onedrive.live.com/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i$document -||onedrive.live.com/download?cid=70d8fa75c83fbdbe&resid=70d8fa75c83fbdbe%21144&authkey=acw8wl1noncfp-4$document ||onedrive.live.com/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam$document ||onedrive.live.com/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble$document ||onedrive.live.com/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60$document @@ -3589,6 +3482,7 @@ ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum$document ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto$document ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum$document +||onedrive.live.com/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm$document ||onedrive.live.com/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125570&authkey=aejqgjglwurnb0a$document ||onedrive.live.com/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq$document ||onedrive.live.com/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k$document @@ -3599,9 +3493,6 @@ ||onedrive.live.com/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny$document ||onedrive.live.com/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s$document ||onedrive.live.com/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs$document -||onedrive.live.com/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli$document -||onedrive.live.com/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18$document -||onedrive.live.com/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli$document ||onedrive.live.com/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm$document ||onedrive.live.com/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8$document ||onedrive.live.com/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm$document @@ -3627,8 +3518,8 @@ ||onedrive.live.com/download?cid=907247dc330a3f33&resid=907247dc330a3f33!254&authkey=ajt5wxegbvzbwqa$document ||onedrive.live.com/download?cid=907247dc330a3f33&resid=907247dc330a3f33!255&authkey=aaimhpp89qmcfhc$document ||onedrive.live.com/download?cid=907247dc330a3f33&resid=907247dc330a3f33%21254&authkey=ajt5wxegbvzbwqa$document -||onedrive.live.com/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s$document ||onedrive.live.com/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my$document +||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc$document ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby$document ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo$document ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti$document @@ -3636,27 +3527,11 @@ ||onedrive.live.com/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8$document ||onedrive.live.com/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o$document ||onedrive.live.com/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!305&authkey=apgh_teb3673nek$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!306&authkey=aibymhcuhqnmrwo$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm$document -||onedrive.live.com/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21305&authkey=apgh_teb3673nek$document ||onedrive.live.com/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m$document ||onedrive.live.com/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w$document ||onedrive.live.com/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk$document ||onedrive.live.com/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk$document ||onedrive.live.com/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k$document -||onedrive.live.com/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli$document ||onedrive.live.com/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm$document ||onedrive.live.com/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue$document ||onedrive.live.com/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma$document @@ -3675,7 +3550,6 @@ ||onedrive.live.com/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8$document ||onedrive.live.com/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq$document ||onedrive.live.com/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq$document -||onedrive.live.com/download?cid=9fb622acb27482ef&resid=9fb622acb27482ef%211197&authkey=aeacibxy2zlyxro$document ||onedrive.live.com/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o$document ||onedrive.live.com/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4$document ||onedrive.live.com/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi$document @@ -3688,7 +3562,6 @@ ||onedrive.live.com/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs$document ||onedrive.live.com/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw$document ||onedrive.live.com/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o$document -||onedrive.live.com/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc$document ||onedrive.live.com/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs$document ||onedrive.live.com/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw$document ||onedrive.live.com/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu$document @@ -3766,9 +3639,6 @@ ||onedrive.live.com/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs$document ||onedrive.live.com/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m$document ||onedrive.live.com/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga$document -||onedrive.live.com/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk$document -||onedrive.live.com/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!362&authkey=alycl9izrvfl7oc$document -||onedrive.live.com/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21362&authkey=alycl9izrvfl7oc$document ||onedrive.live.com/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg$document ||onedrive.live.com/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a$document ||onedrive.live.com/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a$document @@ -3822,6 +3692,7 @@ ||onedrive.live.com/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu$document ||onedrive.live.com/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu$document ||onedrive.live.com/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq$document +||onedrive.live.com/download?cid=e627fc797baa3032&resid=e627fc797baa3032!2324&authkey=aa8i-r7ixmcraha$document ||onedrive.live.com/download?cid=e627fc797baa3032&resid=e627fc797baa3032%212324&authkey=aa8i-r7ixmcraha$document ||onedrive.live.com/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke$document ||onedrive.live.com/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom$document @@ -3836,7 +3707,6 @@ ||onedrive.live.com/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw$document ||onedrive.live.com/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw$document ||onedrive.live.com/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai$document -||onedrive.live.com/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc$document ||onedrive.live.com/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8$document ||onedrive.live.com/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns$document ||onedrive.live.com/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8$document @@ -3846,7 +3716,6 @@ ||onedrive.live.com/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa$document ||onedrive.live.com/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4$document ||onedrive.live.com/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8$document -||onedrive.live.com/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa$document ||onedrive.live.com/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0$document ||onedrive.live.com/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw$document ||onedrive.live.com/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e$document @@ -3855,7 +3724,6 @@ ||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k$document ||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie$document ||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c$document -||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g$document ||onedrive.live.com/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta$document ||onedrive.live.com/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o$document ||onedrive.live.com/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao$document @@ -3875,6 +3743,7 @@ ||onedrive.live.com/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0$document ||onedrive.live.com/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc$document ||onedrive.live.com/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu$document +||onedrive.live.com/download?cid=fd67fafc46d3c687&resid=fd67fafc46d3c687%21473&authkey=aoid_cp-jgffqvm$document ||onedrive.live.com/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm$document ||onedrive.live.com/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w$document ||onedrive.live.com/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm$document @@ -3894,9 +3763,11 @@ ||onedrive.live.com/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta$document ||online.creedglobal.in$document ||onlinestatis.bar$document +||open.rawntech.com$document ||open.warehousesaas.co.uk$document ||opentoronto.org$document ||opolis.io$document +||opticaoptigral.cl$document ||optimus.com.sg$document ||order.bizpeed.com$document ||orientgatewayltd.com$document @@ -3922,7 +3793,6 @@ ||partharaj.me$document ||partsapp.com.br$document ||paste.ee/r/a39ev$document -||paste.ee/r/oitkz$document ||pastebin.com/raw/77jhk0iw$document ||pastebin.com/raw/89hkc7wb$document ||pastebin.com/raw/yqvsvlvq$document @@ -3939,6 +3809,7 @@ ||pd.oceaniarp.net$document ||pemdodo.com$document ||perfumeriamontes.es$document +||periodiche.bar$document ||perpus.onlineman7-jombang.sch.id$document ||perpustekim.untirta.ac.id$document ||pestoclean.co.uk$document @@ -3960,6 +3831,7 @@ ||pointactionsg.com$document ||pokojewewladyslawowie.pl$document ||pole.com.vc$document +||ponchokhana.com$document ||pool.phxdir.com$document ||pooltablemoversdenver.net$document ||portal.premiumpunch.com$document @@ -3970,6 +3842,7 @@ ||prestigehomeautomation.net$document ||preview2.behalen.com$document ||prishaartcreations.com$document +||prismaxis.com$document ||procrossover.ru/wp-content/uploads/2020/10/skoda22.jpg$document ||procrossover.ru/wp-content/uploads/2020/10/skodaqq.jpg$document ||production.sparshims.com$document @@ -4040,7 +3913,6 @@ ||resuco.net$document ||rezkabum.ru$document ||rhema.com.sg$document -||richancyber.info$document ||richmondminerals.co.zm$document ||rinaefoundation.org.za$document ||rinkaisystem-ht.com$document @@ -4049,7 +3921,6 @@ ||rkverify.securestudies.com$document ||robertmcardle.com$document ||robertsinclair.net$document -||romanianpoints.com$document ||ronnietucker.co.uk$document ||roomsvc.servegate.kr$document ||roshnijewellery.com$document @@ -4059,7 +3930,6 @@ ||ruisgood.ru$document ||ruwadalkuwait.com$document ||rydchile.cl$document -||s.51shijuan.com$document ||s.thechinesemuslim.com$document ||sac2.11xii.com$document ||sacredscentsonline.com$document @@ -4094,7 +3964,9 @@ ||sericaasia.com$document ||servicemhkd.myvnc.com$document ||servicemhkd80.myvnc.com$document +||serviciovirtual.com.ar$document ||sexologistpakistan.net$document +||seyranikenger.com.tr$document ||sgb.ac.ke$document ||sgessy.com.br$document ||shaheentbfoundation.com$document @@ -4147,6 +4019,7 @@ ||special-key.cf$document ||spent.com.pl$document ||spetsesyachtcharter.gr$document +||spiritualroot.org$document ||spititourism.com$document ||spittinfire.com$document ||sports-net.de$document @@ -4168,14 +4041,14 @@ ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt$document ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt$document ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt$document +||storage.googleapis.com/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt$document ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt$document ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt$document ||storage.googleapis.com/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg$document -||storage.googleapis.com/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt$document ||storage.googleapis.com/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt$document ||store.ericalgarin.com$document ||stott-thompson.co.uk$document -||streetdemo.yourpageserver.com$document +||stratexec.co.za$document ||suboldesign.com$document ||sumerians.org$document ||sunaryem.com.tr$document @@ -4224,6 +4097,7 @@ ||test.typoten.com$document ||test.wanepghana.org$document ||test1.asistencia247.com$document +||test1.milenial.id$document ||test1.tenplusone.my$document ||test2.basis-web.com$document ||test2.marrenconstruction.ie$document @@ -4248,7 +4122,7 @@ ||theprofinn.com$document ||thesummitpc.net$document ||theurbantutors.com$document -||thientu.net$document +||thirdstringcalifornia.com$document ||thosewebbs.com$document ||thriveink.com$document ||tianangdep.com$document @@ -4258,7 +4132,6 @@ ||timegonebuy.com$document ||tksb.net$document ||tlcc.com.gt$document -||tntmedia.gr$document ||todoapp.cstdevs.com$document ||todocontodo.com.mx$document ||tonydong.com$document @@ -4296,6 +4169,7 @@ ||umwelt-kirchhof.de$document ||unicorpbrunei.com$document ||uniengrisb.com$document +||unisoftcc.com$document ||unyazitelecom.com$document ||upcbpta.com$document ||urbantrapfest.cl$document @@ -4311,7 +4185,9 @@ ||vcah.co.uk$document ||vectarts.com$document ||vegadelcasero.cl$document +||velma-harber30ku.com$document ||vendas.lidiacarmeli.com.br$document +||versualstudio.com$document ||veterinariadrpopui.com$document ||vfocus.net$document ||vienen.gblix.srv.br$document @@ -4340,6 +4216,7 @@ ||w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu$document ||wanepliberia.org$document ||wanepniger.org$document +||weareactum.com$document ||web.eng.ubu.ac.th$document ||web.geetle.ga$document ||web.geomegasoft.net$document @@ -4375,6 +4252,7 @@ ||wonderhawaii.com$document ||woodsytech.com$document ||wordpress.saleensuporte.com.br$document +||workingsolutionsrome.org$document ||wozata.000webhostapp.com$document ||wp.readhere.in$document ||wpdemo.101clients.com.au$document @@ -4396,7 +4274,7 @@ ||yourclub1.com$document ||yourtopdog.com.au$document ||youtubetrainingacademy.com$document -||yp.hnggzyjy.cn$document +||yp.hnggzyjy.cn/common/yz.vbs$document ||yskadvisors.com$document ||yummyyogaudaipur.com$document ||yzkzixun.com$document diff --git a/urlhaus-filter-vivaldi.txt b/urlhaus-filter-vivaldi.txt index 2c71f016..c8cc5422 100644 --- a/urlhaus-filter-vivaldi.txt +++ b/urlhaus-filter-vivaldi.txt @@ -1,5 +1,5 @@ ! Title: Malicious URL Blocklist (Vivaldi) -! Updated: Sat, 03 Apr 2021 00:13:46 UTC +! Updated: Sat, 03 Apr 2021 12:12:28 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -2024,6 +2024,7 @@ ||101.109.78.164$document ||101.109.85.37$document ||101.109.85.40$document +||101.126.102.31$document ||101.126.155.223$document ||101.126.87.66$document ||101.128.72.166$document @@ -3771,6 +3772,7 @@ ||103.217.123.137$document ||103.217.123.14$document ||103.217.123.142$document +||103.217.123.143$document ||103.217.123.145$document ||103.217.123.147$document ||103.217.123.151$document @@ -4420,6 +4422,7 @@ ||103.41.25.189$document ||103.41.25.201$document ||103.41.25.203$document +||103.41.25.206$document ||103.41.25.21$document ||103.41.25.212$document ||103.41.25.233$document @@ -12059,6 +12062,7 @@ ||111.92.80.176$document ||111.92.80.182$document ||111.92.80.183$document +||111.92.80.192$document ||111.92.80.195$document ||111.92.80.196$document ||111.92.80.20$document @@ -20048,6 +20052,7 @@ ||112.80.215.101$document ||112.80.215.227$document ||112.80.215.229$document +||112.80.218.56$document ||112.80.236.136$document ||112.80.236.158$document ||112.80.236.45$document @@ -50019,6 +50024,7 @@ ||115.56.130.27$document ||115.56.130.30$document ||115.56.130.32$document +||115.56.130.33$document ||115.56.130.5$document ||115.56.130.52$document ||115.56.130.55$document @@ -93131,6 +93137,7 @@ ||116.68.97.187$document ||116.68.97.192$document ||116.68.97.193$document +||116.68.97.199$document ||116.68.97.2$document ||116.68.97.204$document ||116.68.97.212$document @@ -116914,6 +116921,7 @@ ||117.202.69.110$document ||117.202.69.111$document ||117.202.69.112$document +||117.202.69.113$document ||117.202.69.114$document ||117.202.69.115$document ||117.202.69.116$document @@ -118555,6 +118563,7 @@ ||117.208.135.217$document ||117.208.135.218$document ||117.208.135.22$document +||117.208.135.220$document ||117.208.135.225$document ||117.208.135.227$document ||117.208.135.229$document @@ -119414,6 +119423,7 @@ ||117.212.52.160$document ||117.212.54.132$document ||117.212.55.67$document +||117.213.10.108$document ||117.213.10.115$document ||117.213.10.125$document ||117.213.10.140$document @@ -119468,6 +119478,7 @@ ||117.213.15.238$document ||117.213.15.29$document ||117.213.15.43$document +||117.213.15.72$document ||117.213.40.10$document ||117.213.40.100$document ||117.213.40.102$document @@ -120940,6 +120951,7 @@ ||117.215.208.107$document ||117.215.208.11$document ||117.215.208.116$document +||117.215.208.14$document ||117.215.208.143$document ||117.215.208.149$document ||117.215.208.153$document @@ -123260,6 +123272,7 @@ ||117.222.169.229$document ||117.222.169.23$document ||117.222.169.231$document +||117.222.169.232$document ||117.222.169.234$document ||117.222.169.236$document ||117.222.169.239$document @@ -129855,6 +129868,7 @@ ||118.24.9.62$document ||118.246.199.1$document ||118.246.246.125$document +||118.246.38.170$document ||118.249.136.112$document ||118.249.136.98$document ||118.249.137.218$document @@ -151900,6 +151914,7 @@ ||123.14.248.189$document ||123.14.248.19$document ||123.14.248.208$document +||123.14.248.210$document ||123.14.248.212$document ||123.14.248.216$document ||123.14.248.221$document @@ -153322,6 +153337,7 @@ ||123.159.30.49$document ||123.159.31.110$document ||123.159.51.112$document +||123.159.68.119$document ||123.159.68.151$document ||123.159.68.26$document ||123.159.68.31$document @@ -153598,6 +153614,7 @@ ||123.191.6.244$document ||123.191.6.93$document ||123.191.60.197$document +||123.191.62.239$document ||123.191.63.187$document ||123.191.7.209$document ||123.191.79.120$document @@ -162359,7 +162376,7 @@ ||123moviesfx.com$document ||123sellfast.com$document ||123sex.co$document -||123tadi.com$document +||123tadi.com/invoice-status/invoice-0321355444-jun-20$document ||123xyz.xyz$document ||124.100.74.153$document ||124.105.105.222$document @@ -202119,6 +202136,7 @@ ||178.141.47.227$document ||178.141.47.70$document ||178.141.48.109$document +||178.141.48.178$document ||178.141.48.43$document ||178.141.48.82$document ||178.141.49.101$document @@ -202600,6 +202618,7 @@ ||178.175.100.58$document ||178.175.100.61$document ||178.175.100.65$document +||178.175.100.7$document ||178.175.100.70$document ||178.175.100.75$document ||178.175.100.77$document @@ -202779,6 +202798,7 @@ ||178.175.102.211$document ||178.175.102.214$document ||178.175.102.216$document +||178.175.102.219$document ||178.175.102.22$document ||178.175.102.220$document ||178.175.102.221$document @@ -203910,6 +203930,7 @@ ||178.175.112.136$document ||178.175.112.138$document ||178.175.112.139$document +||178.175.112.140$document ||178.175.112.147$document ||178.175.112.148$document ||178.175.112.15$document @@ -206285,6 +206306,7 @@ ||178.175.18.27$document ||178.175.18.32$document ||178.175.18.36$document +||178.175.18.37$document ||178.175.18.38$document ||178.175.18.42$document ||178.175.18.45$document @@ -209022,7 +209044,9 @@ ||178.175.43.217$document ||178.175.43.22$document ||178.175.43.220$document +||178.175.43.223$document ||178.175.43.227$document +||178.175.43.229$document ||178.175.43.231$document ||178.175.43.232$document ||178.175.43.234$document @@ -209109,6 +209133,7 @@ ||178.175.44.158$document ||178.175.44.162$document ||178.175.44.165$document +||178.175.44.166$document ||178.175.44.168$document ||178.175.44.169$document ||178.175.44.171$document @@ -212139,6 +212164,7 @@ ||178.175.71.174$document ||178.175.71.175$document ||178.175.71.178$document +||178.175.71.179$document ||178.175.71.180$document ||178.175.71.185$document ||178.175.71.189$document @@ -212862,6 +212888,7 @@ ||178.175.78.234$document ||178.175.78.236$document ||178.175.78.240$document +||178.175.78.242$document ||178.175.78.243$document ||178.175.78.244$document ||178.175.78.246$document @@ -214980,6 +215007,7 @@ ||178.175.97.110$document ||178.175.97.111$document ||178.175.97.112$document +||178.175.97.113$document ||178.175.97.116$document ||178.175.97.118$document ||178.175.97.12$document @@ -217505,6 +217533,7 @@ ||180.188.241.194$document ||180.188.241.2$document ||180.188.241.201$document +||180.188.241.203$document ||180.188.241.215$document ||180.188.241.216$document ||180.188.241.219$document @@ -240023,6 +240052,7 @@ ||182.121.26.242$document ||182.121.26.251$document ||182.121.26.35$document +||182.121.26.37$document ||182.121.26.56$document ||182.121.26.58$document ||182.121.26.77$document @@ -272694,6 +272724,7 @@ ||202.164.138.185$document ||202.164.138.187$document ||202.164.138.188$document +||202.164.138.19$document ||202.164.138.192$document ||202.164.138.195$document ||202.164.138.196$document @@ -277293,6 +277324,7 @@ ||209.14.30.183$document ||209.14.30.204$document ||209.14.30.205$document +||209.14.30.209$document ||209.14.30.212$document ||209.14.30.213$document ||209.14.30.216$document @@ -277319,6 +277351,7 @@ ||209.14.31.190$document ||209.14.31.192$document ||209.14.31.201$document +||209.14.31.209$document ||209.14.31.215$document ||209.14.31.217$document ||209.14.31.220$document @@ -277331,6 +277364,7 @@ ||209.14.31.243$document ||209.14.31.244$document ||209.14.31.247$document +||209.14.31.249$document ||209.14.31.252$document ||209.14.31.253$document ||209.14.31.55$document @@ -277899,6 +277933,7 @@ ||210.18.189.89$document ||210.18.189.9$document ||210.18.189.90$document +||210.180.17.140$document ||210.180.237.212$document ||210.182.101.144$document ||210.182.148.126$document @@ -290874,6 +290909,7 @@ ||220.133.1.130$document ||220.133.103.166$document ||220.133.109.249$document +||220.133.110.157$document ||220.133.114.189$document ||220.133.115.57$document ||220.133.117.229$document @@ -316650,6 +316686,7 @@ ||27.210.29.26$document ||27.210.29.83$document ||27.210.3.50$document +||27.210.32.122$document ||27.210.32.123$document ||27.210.32.125$document ||27.210.32.130$document @@ -318093,6 +318130,7 @@ ||27.216.116.240$document ||27.216.116.81$document ||27.216.117.178$document +||27.216.117.54$document ||27.216.118.234$document ||27.216.119.219$document ||27.216.119.228$document @@ -347342,6 +347380,7 @@ ||36.248.227.203$document ||36.248.228.64$document ||36.248.82.234$document +||36.248.83.98$document ||36.248.88.35$document ||36.248.92.154$document ||36.248.93.13$document @@ -362825,6 +362864,7 @@ ||42.226.83.71$document ||42.226.83.78$document ||42.226.83.98$document +||42.226.85.236$document ||42.226.86.204$document ||42.226.87.123$document ||42.226.88.114$document @@ -365116,6 +365156,7 @@ ||42.228.39.197$document ||42.228.39.2$document ||42.228.39.204$document +||42.228.39.211$document ||42.228.39.212$document ||42.228.39.214$document ||42.228.39.215$document @@ -372867,6 +372908,7 @@ ||42.232.81.147$document ||42.232.81.149$document ||42.232.81.176$document +||42.232.81.179$document ||42.232.81.181$document ||42.232.81.183$document ||42.232.81.188$document @@ -387106,6 +387148,7 @@ ||49.117.191.46$document ||49.117.191.78$document ||49.117.191.83$document +||49.119.187.230$document ||49.119.188.56$document ||49.119.189.124$document ||49.119.189.223$document @@ -390804,6 +390847,7 @@ ||58.248.142.212$document ||58.248.142.214$document ||58.248.142.223$document +||58.248.142.227$document ||58.248.142.23$document ||58.248.142.230$document ||58.248.142.236$document @@ -392043,6 +392087,7 @@ ||58.249.79.16$document ||58.249.79.163$document ||58.249.79.17$document +||58.249.79.174$document ||58.249.79.175$document ||58.249.79.188$document ||58.249.79.195$document @@ -392239,6 +392284,7 @@ ||58.249.84.118$document ||58.249.84.124$document ||58.249.84.128$document +||58.249.84.131$document ||58.249.84.134$document ||58.249.84.148$document ||58.249.84.150$document @@ -403737,6 +403783,7 @@ ||59.96.37.121$document ||59.96.37.122$document ||59.96.37.123$document +||59.96.37.124$document ||59.96.37.125$document ||59.96.37.127$document ||59.96.37.128$document @@ -408159,6 +408206,7 @@ ||59.99.43.187$document ||59.99.43.19$document ||59.99.43.190$document +||59.99.43.191$document ||59.99.43.192$document ||59.99.43.193$document ||59.99.43.194$document @@ -430994,6 +431042,7 @@ ||61.53.89.199$document ||61.53.89.2$document ||61.53.89.208$document +||61.53.89.220$document ||61.53.89.221$document ||61.53.89.227$document ||61.53.89.232$document @@ -432072,6 +432121,7 @@ ||61.54.69.62$document ||61.54.69.69$document ||61.54.69.70$document +||61.54.69.77$document ||61.54.69.78$document ||61.54.69.8$document ||61.54.69.95$document @@ -446658,7 +446708,7 @@ ||app.boxrcdn.com$document ||app.bridgeimpex.org$document ||app.calag.at$document -||app.casetabs.com$document +||app.casetabs.com/n/p7nx8575$document ||app.catholicchurch.co.in$document ||app.choiphui.com$document ||app.cloudindustry.net$document @@ -451118,6 +451168,7 @@ ||beansmedia.com$document ||beanssur.com$document ||beantreefoods.com$document +||beanx88.xyz$document ||beanz-network.com$document ||bearcatpumps.com.cn$document ||beard-companies.com$document @@ -458909,7 +458960,7 @@ ||cdnpic.mgyun.com$document ||cdnrep.reimage.com/prot/protectorpackagerr2023.exe$document ||cdnrep.reimage.com/ver/reimagepackage1874x64b.exe$document -||cdnrep.reimageplus.com$document +||cdnrep.reimageplus.com/rqt/reimagerepair.exe$document ||cdnxh.net$document ||cdoconsult.com.br$document ||cdolechon.com$document @@ -459665,7 +459716,7 @@ ||cheapgadgets-gq.000webhostapp.com$document ||cheapistan.pk$document ||cheapmlbjerseysmarlins.com$document -||cheapmusic.info$document +||cheapmusic.info/cloudnet.exe$document ||cheapnikeairmaxshoes-online.com/0866x/sep/business$document ||cheapnikeairmaxshoes-online.com/0866x/sep/business/$document ||cheapnikeairmaxshoes-online.com/eri8g1mtcmqdynau9plb/swift/200-jahre$document @@ -459722,7 +459773,7 @@ ||cheematransxpressinc.com$document ||cheerchile.cl$document ||cheerfulgiversneverlack.com$document -||cheerfullydo.com$document +||cheerfullydo.com/data/nhtlrr/94046/nbar_94046_29052020.zip$document ||cheesecakery.com.br$document ||cheetahridge.mediadevstaging.com$document ||chef-solutions.dreamscape.co.in$document @@ -460170,8 +460221,7 @@ ||christinablunsum.com$document ||christinailoveyousomuchyoumyheart.duckdns.org$document ||christinalenway.com$document -||christinekeller.ch/wp-content/uploads/document/840880756/0s7m3d-40676/$document -||christinekeller.ch/wp-content/uploads/eo4iqgqw-nb3k8-4084/$document +||christinekeller.ch$document ||christinelebeck.com$document ||christinewalker.org/wp-admin/xt9snhtexu/$document ||christinmunsch.com$document @@ -466012,7 +466062,7 @@ ||demo.jrkcompany.com$document ||demo.kalapifoods.com$document ||demo.kanapebudapest.hu$document -||demo.kechuahangdidong.com/assets/file/h-585-50-xjfl8wz-oariqb/$document +||demo.kechuahangdidong.com$document ||demo.kzonetechnologies.com$document ||demo.lamppostmedia.in$document ||demo.lapizblanco.com$document @@ -468176,7 +468226,8 @@ ||dl-675423.store-downloads.com$document ||dl-80076342.md-downloads.com$document ||dl-97674424.md-downloads.com$document -||dl-gameplayer.dmm.com$document +||dl-gameplayer.dmm.com/product/apkggame/giga_baldrbringerextendcode/giga_baldrbringerextendcode/win/src/content/data/data/uninstall.exe$document +||dl-gameplayer.dmm.com/product/apkggame/nel_narikiri/nel_narikiri/win/src/content/data/%e3%81%aa%e3%82%8a%e3%81%8d%e3%82%8a%e3%83%90%e3%82%ab%e3%83%83%e3%83%97%e3%83%ab%ef%bc%81.exe$document ||dl-link.link$document ||dl-link.live$document ||dl-link.network$document @@ -468504,7 +468555,7 @@ ||dl.rina-roleplay.com$document ||dl.river-store.com$document ||dl.rp-soft.ir$document -||dl.softservers.net$document +||dl.softservers.net/111000667/optimizerpro.exe%20%20d.tubedimmerapp.com/updater/setup4.exe$document ||dl.svcupdate.com$document ||dl.teeqee.com$document ||dl.x420.me$document @@ -470757,8 +470808,10 @@ ||down.post-gg.top$document ||down.postch-b.top$document ||down.postch-bsw.top$document +||down.postch-de.top$document ||down.postch-dfa.top$document ||down.postch-dj.top$document +||down.postch-dl.top$document ||down.postch-fa.top$document ||down.postch-fj.top$document ||down.postch-kf.top$document @@ -487403,7 +487456,8 @@ ||economiadigital.biz$document ||economika.com.ve$document ||economizei.shop$document -||economplast.com$document +||economplast.com/lypumytb/d4/ce/a64bze4c.zip$document +||economplast.com/lypumytb/ma/25/tt18os7d.zip$document ||economywindowcleaner.com$document ||econoteen.fea.usp.br$document ||econotel.us$document @@ -492360,7 +492414,9 @@ ||files.gamebanana.com/tools/enchanced_server_picker.exe$document ||files.gamebanana.com/tools/tagconverter.exe$document ||files.gathercdn.com$document -||files.hrloo.com$document +||files.hrloo.com/bbs/data/attachment/forum/201212/20/10301044ex3m3s62emr1r7.doc$document +||files.hrloo.com/bbs/data/attachment/forum/201212/20/10301044ex3m3s62emr1r7.doc?n=w+eyvuwtgv3lkzjlt6xln7norq3nrqhnkiblilbluqyuzg9j$document +||files.hrloo.com/bbs/data/attachment/forum/201212/20/10301044ex3m3s62emr1r7.doc?n=weyvuwtgv3lkzjlt6xln7norq3nrqhnkiblilbluqyuzg9j$document ||files.jivosite.com/file-transfer/1621967/2021-03-16/55ec600e4e6500e080c5.doc$document ||files.l-d.tech$document ||files.lashawnbarber.com/$document @@ -494721,8 +494777,7 @@ ||fv13.failiem.lv$document ||fv15.failiem.lv$document ||fv2-1.failiem.lv/down.php?cf&i=hyg2rxaa&n=new_payment.doc&download_checksum=afa67b9a5998eca281cda22f5585e9dcf764128a&download_timestamp=1547330846$document -||fv2-2.failiem.lv/down.php?cf&i=my59dhhv&n=2562.xls$document -||fv2-2.failiem.lv/down.php?cf&i=redm59qf&n=dfg-016.xls$document +||fv2-2.failiem.lv$document ||fv2-7.failiem.lv$document ||fv3.failiem.lv$document ||fv6.failiem.lv$document @@ -499232,7 +499287,7 @@ ||hangtrentroi.com$document ||hangulcafes.ga$document ||hanh.cz$document -||hanhtrinhtamlinh.com$document +||hanhtrinhtamlinh.com/gpk/personal-section/verifiable-space/d3d-660ut9x793v61/$document ||hanhtrinhthanhnienkhoinghiep.vn$document ||haniamarket.com$document ||hanict.org.vn$document @@ -499435,7 +499490,8 @@ ||harriscustomcatering.com$document ||harrisheatpumps.nz$document ||harrisnewtech.ir$document -||harrisoncarter.com$document +||harrisoncarter.com/3578001584444_ycu75_resource/kkc/$document +||harrisoncarter.com/3578001584444_ycu75_resource/yzgvvr/$document ||harrisonlily.co.uk$document ||harryfang.com$document ||harryhiggins.com$document @@ -502353,7 +502409,7 @@ ||i.cubeupload.com/euev6n.jpg$document ||i.cubeupload.com/ez3vpt.jpg$document ||i.cubeupload.com/gmetap.jpg$document -||i.fiery.me$document +||i.fiery.me/5vdk.png$document ||i.fluffy.cc$document ||i.funtourspt.eu$document ||i.imgur.com/3zblzb6.png$document @@ -508974,8 +509030,7 @@ ||kec-cendana.enrekangkab.go.id$document ||kec-wlingi.blitarkab.go.id$document ||kecforging.com$document -||kechuahangdidong.com/wp-admin/esp/0ebq5jmrn3i6/6qh4jn-346396224-48-1pa3isys-ble49fo32t5/$document -||kechuahangdidong.com/wp-admin/mncrbbx/6xpzk58cu/4-4637795257-79951-vdhdt1n26o-r0w7n/$document +||kechuahangdidong.com$document ||keciorenkoltukyikama.net$document ||keckarangdadap.pekalongankab.go.id$document ||kecsfila.hu$document @@ -530191,23 +530246,7 @@ ||ossandonycia.cl$document ||osscaar.com$document ||osservatore.betacom.it$document -||ossi4.51cto.com/attachment/201203/4594712_1333015433.rar$document -||ossi4.51cto.com/attachment/201204/4594712_1334794324.rar$document -||ossi4.51cto.com/attachment/201204/4594712_1335670976.rar$document -||ossi4.51cto.com/attachment/201205/4594712_1336127240.rar$document -||ossi4.51cto.com/attachment/201205/4594712_1337420961.rar$document -||ossi4.51cto.com/attachment/201205/4594712_1337853814.rar$document -||ossi4.51cto.com/attachment/201205/4594712_1337902068.rar$document -||ossi4.51cto.com/attachment/201205/4594712_1338219299.rar$document -||ossi4.51cto.com/attachment/201206/4594712_1338596584.rar$document -||ossi4.51cto.com/attachment/201206/4594712_1338631130.rar$document -||ossi4.51cto.com/attachment/201206/4594712_1338940618.rar$document -||ossi4.51cto.com/attachment/201206/4594712_1339042034.rar$document -||ossi4.51cto.com/attachment/201206/4594712_1339151181.rar$document -||ossi4.51cto.com/attachment/201206/4594712_1339214458.rar$document -||ossi4.51cto.com/attachment/201206/4594712_1339410537.rar$document -||ossi4.51cto.com/attachment/201206/4594712_1339456815.rar$document -||ossi4.51cto.com/attachment/201206/5305206_1339979954.rar$document +||ossi4.51cto.com$document ||ossianlaw.com$document ||osslusturv.com$document ||ossoriobouliz.com$document @@ -539673,7 +539712,7 @@ ||politrix.net$document ||poliyzsl.host$document ||poljimenez.com$document -||polk.k12.ga.us/userfiles/13/classes/2473/8thpssyllabus.doc$document +||polk.k12.ga.us$document ||polka32.ru$document ||polkapower.com$document ||polkolonieb4k.pl$document @@ -540873,7 +540912,8 @@ ||professionalwaiterskollege.org$document ||professionelelit.com$document ||professorsgallery.com$document -||profetestruec.net$document +||profetestruec.net:8000/in3.ps1$document +||profetestruec.net:8000/in6.ps1$document ||profexsystem.com$document ||proffessia.ru$document ||proffice.com.pl$document @@ -541264,9 +541304,7 @@ ||protect-us.mimecast.com/s/7ihcc82oqycqx96qh15qw5$document ||protect-us.mimecast.com/s/c27ac0rx9ru80p3fw0bgj$document ||protect-us.mimecast.com/s/qki9c73wxjupxq5ps8qcm_$document -||protect.mimecast-offshore.com/s/ip17cn9blzfnq4n4h4tudd?domain=meraqsa.com/$document -||protect.mimecast-offshore.com/s/loqwcg5rvpcjndxqc76apn?domain=ronakfence.ir/$document -||protect.mimecast-offshore.com/s/rd0zcjqxyvf8w6o3igppxq?domain=ronakfence.ir/$document +||protect.mimecast-offshore.com$document ||protect2.fireeye.com/v1/url?k=59eacb3c-0560e9d5-59ed97de-0cc47ad93e2e-0f5e34e79adab692&q=1&e=e7991bbc-cc93-4814-a8f2-fd6d6950b0d5&u=https%3a%2f%2fwww.mediafire.com%2ffile%2fs2uyxs8t8kbuyye%2fdocumentos_de_env%25cdo.7z%2ffile$document ||protect2.fireeye.com/v1/url?k=6d0c09d2-33bdd2b2-6d0f7943-86e2237f51fb-ab55eb53c2dfee1f&q=1&e=358c9b57-d351-4b0f-80cf-d0755ec21127&u=https://pottershousedurban.co.za/cgi-bin/file/xzbx0cb5wywuw5/179vj6b9dpsp7advozp/$document ||protectiadatelor.biz$document @@ -549985,7 +550023,7 @@ ||shared.outlook.inky.com/link?domain=www.toziba.ir&t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdunfugkaq_jd7tqby28qtte2siucq4akhiquccnh36heusom_93hq0odndjazm7p7jrqbtgtkoxmvihjsn4atsxnae0sfiliaq_yjwemmigieajwaghr4flxxomyqraaocn-olxohlupdgzsxe7prokpvd5qbqawg1wcoobwjkz3ufhzxrsqdhoeov97zesjd3ud42czjzno6tbykppb0q2sllrejuqukofjgvoh2meqyo3nmwrvhrrxjjy_wjowcvdf-eyutqxtbpcsvrxzwosy4xzirljn8gab75zz7x9l-wuzbwemg7on1all8m9bux-5uz2yu_7siifpeuvfexnqvcu5-4aze-6xfvs5svlghmixjb1iockmarmeqzkscgzgr_7818pqjn19jvyhz.meyciqdjb9hlkixl4sz_rt8-tj8v7t6tzcbxfjgcuyhbc8ixuwihapwstswmgpu_k43h-va03ffjltif7n-k3qrucylug8il/$document ||shared.outlook.inky.com/link?domain=www.toziba.ir/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxduf1vgjau_s99dqa4t-mtbcbortbrpqqhireoqmmllilisv--8rrkj-fm3pp1jrqbxuzogu6lajgr-gscydidneklueqkyghxataqeskap0d1icdpx5-xhepmyfztb4u_1er9gwqlls0inmoz6zpd1y8ybaougl6eioelie1pd1fvuhzk2mfxau_wb173mbp_9kvnloytl6c1ida15m5hc9eynkkqkaruwsinajexjjmyy87akjxrhm55fe5yxhmndvmrtoiww3ewve8cwlmrcpelfi7smoghdistd2_pyu4jwk0iz-ncvdrjbzn2vt13vv4de76-4cqhacp8i-kpt7tl7cfos3vxc_otje5d44bihawljjdnkjsnzktprjwzkcv_2xpzzdhpl9e5g6k.meucigd6xwariut2lkiettiajcosxyluv7ub6nhbepewswmwaiea4mzpunjaca7lslweyqnda4gpvqjwhufuenzur1jmp64//$document ||shared.outlook.inky.com/link?domain=www.toziba.ir/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdunfugkaq_jd7tqby28qtte2siucq4akhiquccnh36heusom_93hq0odndjazm7p7jrqbtgtkoxmvihjsn4atsxnae0sfiliaq_yjwemmigieajwaghr4flxxomyqraaocn-olxohlupdgzsxe7prokpvd5qbqawg1wcoobwjkz3ufhzxrsqdhoeov97zesjd3ud42czjzno6tbykppb0q2sllrejuqukofjgvoh2meqyo3nmwrvhrrxjjy_wjowcvdf-eyutqxtbpcsvrxzwosy4xzirljn8gab75zz7x9l-wuzbwemg7on1all8m9bux-5uz2yu_7siifpeuvfexnqvcu5-4aze-6xfvs5svlghmixjb1iockmarmeqzkscgzgr_7818pqjn19jvyhz.meyciqdjb9hlkixl4sz_rt8-tj8v7t6tzcbxfjgcuyhbc8ixuwihapwstswmgpu_k43h-va03ffjltif7n-k3qrucylug8il//$document -||shared.pdffiller.com$document +||shared.pdffiller.com/1395f7beaf30f1943ac9e1b9800a8fbf/8c7dd922ad47494fc02c388e12c00eac/cdecfead5bd78cb1c29f931bc49ad2db.exe?t=1549302986$document ||shareddocuments.ml$document ||shareddynamics.com$document ||sharedeconomy.eu$document @@ -557423,7 +557461,7 @@ ||supadom.fr$document ||supamidland-my.sharepoint.com$document ||supcargo.com$document -||supdate.mediaweb.co.kr/download/pica/client/data/uninstall_1.exe$document +||supdate.mediaweb.co.kr$document ||super-filtr.ru$document ||super-gamezer.com$document ||super-industries.co$document @@ -562215,7 +562253,7 @@ ||tldrnet.top/winsysdrv.exe$document ||tlextreme.com$document ||tlfthelifefactory.com.au$document -||tlgur.com$document +||tlgur.com/d/8lop0bv4/$document ||tlkcloudem.com$document ||tlktdsfj.sha58.me$document ||tlpclient.site$document @@ -563935,7 +563973,7 @@ ||tsr-mark.xyz$document ||tsredco.telangana.gov.in$document ||tsrj.monster$document -||tsrv2.top/telikkk.exe$document +||tsrv2.top$document ||tsrv4.ws/23.exe$document ||tst.marineindust.com$document ||tstfrigo.com$document @@ -566022,9 +566060,7 @@ ||update-prog.com$document ||update-res.100public.com$document ||update.5v.pl$document -||update.7h4uk.com:443/antitrojan.ps1$document -||update.7h4uk.com:443/cohernece.txt$document -||update.7h4uk.com:443/logos.png$document +||update.7h4uk.com$document ||update.att.tools$document ||update.bracncet.net$document ||update.bruss.org.ru$document @@ -566315,7 +566351,7 @@ ||url.emailprotection.link/?bgmvicpuho15c9_q9hiofgnmkaco0q_lujjcaeowkfik_hdtt1uqmbkpovhxykckgjoqoytv_u0g2umkhd4mbi9ms8vo3vliq2clouuaa6no2a7ij5ljfsouoeememvmi/$document ||url.emailprotection.link/?bizyxbw1fdagsfcc1n6ep1awpdx9dr0brnjjqwgyaofpw98limviipvrszjnzzluclpeqqdywfxwnwudvwrljcufuhl2_nha0bs8wz9jmbahcciikbseljewayzbe_cnd/$document ||url.sg/rwtho$document -||url2.mailanyone.net/v1/?m=1hibcm-0003zv-63&i=57e1b682&c=sb1blj46bk32u6f729r5t_slvkx-heewxh20_zdn9-3ktcc0-kn35fykilpydgeyvrbwqwb5h__fk383wtdakqftjlelxz06jbaglri5jmujnydjkasqxwdtg2hn-_be1dzrnthvvhigyhm_tvbew342habp8dtit9jjlieuc2x-ipgdgipe7y_c9jhe69532gmnxozb5wifjfbstzicagmtpg6yxmreaf0sq2dgo-ksy54hetfhn6gwm4kiw2vvcqx17a9bm6ykn8bwpwdjwg/$document +||url2.mailanyone.net$document ||url3.mailanyone.net$document ||url5459.41southbar.com$document ||url675.textilmallorca.com$document @@ -567781,7 +567817,7 @@ ||viettrust-vn.net$document ||vietucgroup.org$document ||vietup.net$document -||vietvictory.vn$document +||vietvictory.vn/wp-content/themes/eikra-child/languages/1c.jpg$document ||vievioparapija.eu$document ||view-indonesia.com$document ||view-your-website.com$document @@ -568240,8 +568276,7 @@ ||visualblends.com$document ||visualdata.ru$document ||visualdimensioniq.com$document -||visualdive.com/wp-admin/balance/4343726113/u2r5u-00497429/$document -||visualdive.com/wp-content/k8kibhjxoc03akqd0hampdubw8dg8zgiuo3pcqu6lbns5b5yrs4ky/$document +||visualdive.com$document ||visualendodontics.net$document ||visualgag.co.uk$document ||visualhome.cl$document @@ -569359,7 +569394,7 @@ ||wc3prince.ru$document ||wcare.nl$document ||wcbgroup.co.uk$document -||wcdownloadercdn.lavasoft.com$document +||wcdownloadercdn.lavasoft.com/4.3.1908.3686/wcinstaller.exe$document ||wcdr.pbas.es$document ||wcf-old.sibcat.info$document ||wcfamlaw.com$document @@ -571088,6 +571123,7 @@ ||workingonit.site$document ||workingpainters.com$document ||workingroofers.com$document +||workingsolutionsrome.org$document ||workingwell.club$document ||worklinic.com.br$document ||workmate-sien.com$document @@ -573549,7 +573585,7 @@ ||yoyoso.nz$document ||yoyoteacher.cn$document ||yp.dcyazilim.com$document -||yp.hnggzyjy.cn$document +||yp.hnggzyjy.cn/common/yz.vbs$document ||ypbb.or.id$document ||ypddf.org$document ||ypicsdy.cf$document @@ -574534,8 +574570,7 @@ ||zoox.com.br$document ||zoparo.nl$document ||zopbxtjiuykhyyp.usa.cc$document -||zopro.duckdns.org/cbsmsg.zip$document -||zopro.duckdns.org/cbsmsg1.zip$document +||zopro.duckdns.org$document ||zoracle.com$document ||zorancreative.com$document ||zoratech.ro$document diff --git a/urlhaus-filter.tpl b/urlhaus-filter.tpl index 29f0b303..8fad9929 100644 --- a/urlhaus-filter.tpl +++ b/urlhaus-filter.tpl @@ -1,6 +1,6 @@ msFilterList # Title: Malicious Hosts Blocklist (IE) -# Updated: Sat, 03 Apr 2021 00:13:46 UTC +# Updated: Sat, 03 Apr 2021 12:12:28 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -241,7 +241,6 @@ msFilterList -d 123moviesfx.com -d 123sellfast.com -d 123sex.co --d 123tadi.com -d 123xyz.xyz -d 124.com.ua -d 124.cpanel.realwebsitesite.com @@ -7097,7 +7096,6 @@ msFilterList -d app.boxrcdn.com -d app.bridgeimpex.org -d app.calag.at --d app.casetabs.com -d app.catholicchurch.co.in -d app.choiphui.com -d app.cloudindustry.net @@ -11329,6 +11327,7 @@ msFilterList -d beansmedia.com -d beanssur.com -d beantreefoods.com +-d beanx88.xyz -d beanz-network.com -d bearcatpumps.com.cn -d beard-companies.com @@ -17630,7 +17629,6 @@ msFilterList -d cdndownloadlp.club -d cdnmultimedia.com -d cdnpic.mgyun.com --d cdnrep.reimageplus.com -d cdnxh.net -d cdoconsult.com.br -d cdolechon.com @@ -18373,7 +18371,6 @@ msFilterList -d cheapgadgets-gq.000webhostapp.com -d cheapistan.pk -d cheapmlbjerseysmarlins.com --d cheapmusic.info -d cheapoakleysunglasses.net -d cheappigeontraps.com -d cheapraccoontraps.com @@ -18422,7 +18419,6 @@ msFilterList -d cheematransxpressinc.com -d cheerchile.cl -d cheerfulgiversneverlack.com --d cheerfullydo.com -d cheesecakery.com.br -d cheetahridge.mediadevstaging.com -d chef-solutions.dreamscape.co.in @@ -18861,6 +18857,7 @@ msFilterList -d christinablunsum.com -d christinailoveyousomuchyoumyheart.duckdns.org -d christinalenway.com +-d christinekeller.ch -d christinelebeck.com -d christinmunsch.com -d christmasatredeemer.org @@ -24431,6 +24428,7 @@ msFilterList -d demo.jrkcompany.com -d demo.kalapifoods.com -d demo.kanapebudapest.hu +-d demo.kechuahangdidong.com -d demo.kzonetechnologies.com -d demo.lamppostmedia.in -d demo.lapizblanco.com @@ -26495,7 +26493,6 @@ msFilterList -d dl-675423.store-downloads.com -d dl-80076342.md-downloads.com -d dl-97674424.md-downloads.com --d dl-gameplayer.dmm.com -d dl-link.link -d dl-link.live -d dl-link.network @@ -26526,7 +26523,6 @@ msFilterList -d dl.rina-roleplay.com -d dl.river-store.com -d dl.rp-soft.ir --d dl.softservers.net -d dl.svcupdate.com -d dl.teeqee.com -d dl.x420.me @@ -27329,8 +27325,10 @@ msFilterList -d down.post-gg.top -d down.postch-b.top -d down.postch-bsw.top +-d down.postch-de.top -d down.postch-dfa.top -d down.postch-dj.top +-d down.postch-dl.top -d down.postch-fa.top -d down.postch-fj.top -d down.postch-kf.top @@ -29141,7 +29139,6 @@ msFilterList -d economiadigital.biz -d economika.com.ve -d economizei.shop --d economplast.com -d economywindowcleaner.com -d econoteen.fea.usp.br -d econotel.us @@ -33850,7 +33847,6 @@ msFilterList -d files.dropmybin.me -d files.enjin.com -d files.gathercdn.com --d files.hrloo.com -d files.l-d.tech -d files.martellexpress.us -d files.mirai-2viv.vn @@ -36063,6 +36059,7 @@ msFilterList -d fv1-2.failiem.lv -d fv13.failiem.lv -d fv15.failiem.lv +-d fv2-2.failiem.lv -d fv2-7.failiem.lv -d fv3.failiem.lv -d fv6.failiem.lv @@ -40306,7 +40303,6 @@ msFilterList -d hangtrentroi.com -d hangulcafes.ga -d hanh.cz --d hanhtrinhtamlinh.com -d hanhtrinhthanhnienkhoinghiep.vn -d haniamarket.com -d hanict.org.vn @@ -40501,7 +40497,6 @@ msFilterList -d harriscustomcatering.com -d harrisheatpumps.nz -d harrisnewtech.ir --d harrisoncarter.com -d harrisonlily.co.uk -d harryfang.com -d harryhiggins.com @@ -43302,7 +43297,6 @@ msFilterList -d i-supportcharity.com -d i-vnsweyu.pl -d i-voda.com --d i.fiery.me -d i.fluffy.cc -d i.funtourspt.eu -d i.ooxx.ooo @@ -49683,6 +49677,7 @@ msFilterList -d kec-cendana.enrekangkab.go.id -d kec-wlingi.blitarkab.go.id -d kecforging.com +-d kechuahangdidong.com -d keciorenkoltukyikama.net -d keckarangdadap.pekalongankab.go.id -d kecsfila.hu @@ -67486,6 +67481,7 @@ msFilterList -d ossandonycia.cl -d osscaar.com -d osservatore.betacom.it +-d ossi4.51cto.com -d ossianlaw.com -d osslusturv.com -d ossoriobouliz.com @@ -70818,6 +70814,7 @@ msFilterList -d politrix.net -d poliyzsl.host -d poljimenez.com +-d polk.k12.ga.us -d polka32.ru -d polkapower.com -d polkolonieb4k.pl @@ -71989,7 +71986,6 @@ msFilterList -d professionalwaiterskollege.org -d professionelelit.com -d professorsgallery.com --d profetestruec.net -d profexsystem.com -d proffessia.ru -d proffice.com.pl @@ -72367,6 +72363,7 @@ msFilterList -d protech.mn -d protechcarpetcare.com -d protechgroup1.com +-d protect.mimecast-offshore.com -d protectiadatelor.biz -d protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org -d protection.pecol.eu @@ -80473,7 +80470,6 @@ msFilterList -d sharebook.tk -d sharechautari.com -d shared-cnd.com --d shared.pdffiller.com -d shareddocuments.ml -d shareddynamics.com -d sharedeconomy.eu @@ -86102,6 +86098,7 @@ msFilterList -d supadom.fr -d supamidland-my.sharepoint.com -d supcargo.com +-d supdate.mediaweb.co.kr -d super-filtr.ru -d super-gamezer.com -d super-industries.co @@ -90720,7 +90717,6 @@ msFilterList -d tldrbox.top -d tlextreme.com -d tlfthelifefactory.com.au --d tlgur.com -d tlkcloudem.com -d tlktdsfj.sha58.me -d tlpclient.site @@ -92356,6 +92352,7 @@ msFilterList -d tsr-mark.xyz -d tsredco.telangana.gov.in -d tsrj.monster +-d tsrv2.top -d tst.marineindust.com -d tstfrigo.com -d tsugite.youbi.me @@ -93767,6 +93764,7 @@ msFilterList -d update-prog.com -d update-res.100public.com -d update.5v.pl +-d update.7h4uk.com -d update.att.tools -d update.bracncet.net -d update.bruss.org.ru @@ -94006,6 +94004,7 @@ msFilterList -d url-validation-clients.com -d url.246546.com -d url.57569.fr.snd52.ch +-d url2.mailanyone.net -d url3.mailanyone.net -d url5459.41southbar.com -d url675.textilmallorca.com @@ -95404,7 +95403,6 @@ msFilterList -d viettrust-vn.net -d vietucgroup.org -d vietup.net --d vietvictory.vn -d vievioparapija.eu -d view-indonesia.com -d view-your-website.com @@ -95858,6 +95856,7 @@ msFilterList -d visualblends.com -d visualdata.ru -d visualdimensioniq.com +-d visualdive.com -d visualendodontics.net -d visualgag.co.uk -d visualhome.cl @@ -96936,7 +96935,6 @@ msFilterList -d wc3prince.ru -d wcare.nl -d wcbgroup.co.uk --d wcdownloadercdn.lavasoft.com -d wcdr.pbas.es -d wcf-old.sibcat.info -d wcfamlaw.com @@ -98602,6 +98600,7 @@ msFilterList -d workingonit.site -d workingpainters.com -d workingroofers.com +-d workingsolutionsrome.org -d workingwell.club -d worklinic.com.br -d workmate-sien.com @@ -100968,7 +100967,6 @@ msFilterList -d yoyoso.nz -d yoyoteacher.cn -d yp.dcyazilim.com --d yp.hnggzyjy.cn -d ypbb.or.id -d ypddf.org -d ypicsdy.cf @@ -101917,6 +101915,7 @@ msFilterList -d zoox.com.br -d zoparo.nl -d zopbxtjiuykhyyp.usa.cc +-d zopro.duckdns.org -d zoracle.com -d zorancreative.com -d zoratech.ro diff --git a/urlhaus-filter.txt b/urlhaus-filter.txt index d091ba91..cfad1dad 100644 --- a/urlhaus-filter.txt +++ b/urlhaus-filter.txt @@ -1,5 +1,5 @@ ! Title: Malicious URL Blocklist -! Updated: Sat, 03 Apr 2021 00:13:46 UTC +! Updated: Sat, 03 Apr 2021 12:12:28 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -2024,6 +2024,7 @@ 101.109.78.164 101.109.85.37 101.109.85.40 +101.126.102.31 101.126.155.223 101.126.87.66 101.128.72.166 @@ -3771,6 +3772,7 @@ 103.217.123.137 103.217.123.14 103.217.123.142 +103.217.123.143 103.217.123.145 103.217.123.147 103.217.123.151 @@ -4420,6 +4422,7 @@ 103.41.25.189 103.41.25.201 103.41.25.203 +103.41.25.206 103.41.25.21 103.41.25.212 103.41.25.233 @@ -12058,6 +12061,7 @@ 111.92.80.176 111.92.80.182 111.92.80.183 +111.92.80.192 111.92.80.195 111.92.80.196 111.92.80.20 @@ -20047,6 +20051,7 @@ 112.80.215.101 112.80.215.227 112.80.215.229 +112.80.218.56 112.80.236.136 112.80.236.158 112.80.236.45 @@ -50018,6 +50023,7 @@ 115.56.130.27 115.56.130.30 115.56.130.32 +115.56.130.33 115.56.130.5 115.56.130.52 115.56.130.55 @@ -93130,6 +93136,7 @@ 116.68.97.187 116.68.97.192 116.68.97.193 +116.68.97.199 116.68.97.2 116.68.97.204 116.68.97.212 @@ -116913,6 +116920,7 @@ 117.202.69.110 117.202.69.111 117.202.69.112 +117.202.69.113 117.202.69.114 117.202.69.115 117.202.69.116 @@ -118554,6 +118562,7 @@ 117.208.135.217 117.208.135.218 117.208.135.22 +117.208.135.220 117.208.135.225 117.208.135.227 117.208.135.229 @@ -119413,6 +119422,7 @@ 117.212.52.160 117.212.54.132 117.212.55.67 +117.213.10.108 117.213.10.115 117.213.10.125 117.213.10.140 @@ -119467,6 +119477,7 @@ 117.213.15.238 117.213.15.29 117.213.15.43 +117.213.15.72 117.213.40.10 117.213.40.100 117.213.40.102 @@ -120939,6 +120950,7 @@ 117.215.208.107 117.215.208.11 117.215.208.116 +117.215.208.14 117.215.208.143 117.215.208.149 117.215.208.153 @@ -123259,6 +123271,7 @@ 117.222.169.229 117.222.169.23 117.222.169.231 +117.222.169.232 117.222.169.234 117.222.169.236 117.222.169.239 @@ -129854,6 +129867,7 @@ 118.24.9.62 118.246.199.1 118.246.246.125 +118.246.38.170 118.249.136.112 118.249.136.98 118.249.137.218 @@ -151897,6 +151911,7 @@ 123.14.248.189 123.14.248.19 123.14.248.208 +123.14.248.210 123.14.248.212 123.14.248.216 123.14.248.221 @@ -153319,6 +153334,7 @@ 123.159.30.49 123.159.31.110 123.159.51.112 +123.159.68.119 123.159.68.151 123.159.68.26 123.159.68.31 @@ -153595,6 +153611,7 @@ 123.191.6.244 123.191.6.93 123.191.60.197 +123.191.62.239 123.191.63.187 123.191.7.209 123.191.79.120 @@ -162356,7 +162373,6 @@ 123moviesfx.com 123sellfast.com 123sex.co -123tadi.com 123xyz.xyz 124.100.74.153 124.105.105.222 @@ -202115,6 +202131,7 @@ 178.141.47.227 178.141.47.70 178.141.48.109 +178.141.48.178 178.141.48.43 178.141.48.82 178.141.49.101 @@ -202596,6 +202613,7 @@ 178.175.100.58 178.175.100.61 178.175.100.65 +178.175.100.7 178.175.100.70 178.175.100.75 178.175.100.77 @@ -202775,6 +202793,7 @@ 178.175.102.211 178.175.102.214 178.175.102.216 +178.175.102.219 178.175.102.22 178.175.102.220 178.175.102.221 @@ -203906,6 +203925,7 @@ 178.175.112.136 178.175.112.138 178.175.112.139 +178.175.112.140 178.175.112.147 178.175.112.148 178.175.112.15 @@ -206281,6 +206301,7 @@ 178.175.18.27 178.175.18.32 178.175.18.36 +178.175.18.37 178.175.18.38 178.175.18.42 178.175.18.45 @@ -209018,7 +209039,9 @@ 178.175.43.217 178.175.43.22 178.175.43.220 +178.175.43.223 178.175.43.227 +178.175.43.229 178.175.43.231 178.175.43.232 178.175.43.234 @@ -209105,6 +209128,7 @@ 178.175.44.158 178.175.44.162 178.175.44.165 +178.175.44.166 178.175.44.168 178.175.44.169 178.175.44.171 @@ -212135,6 +212159,7 @@ 178.175.71.174 178.175.71.175 178.175.71.178 +178.175.71.179 178.175.71.180 178.175.71.185 178.175.71.189 @@ -212858,6 +212883,7 @@ 178.175.78.234 178.175.78.236 178.175.78.240 +178.175.78.242 178.175.78.243 178.175.78.244 178.175.78.246 @@ -214976,6 +215002,7 @@ 178.175.97.110 178.175.97.111 178.175.97.112 +178.175.97.113 178.175.97.116 178.175.97.118 178.175.97.12 @@ -217501,6 +217528,7 @@ 180.188.241.194 180.188.241.2 180.188.241.201 +180.188.241.203 180.188.241.215 180.188.241.216 180.188.241.219 @@ -240019,6 +240047,7 @@ 182.121.26.242 182.121.26.251 182.121.26.35 +182.121.26.37 182.121.26.56 182.121.26.58 182.121.26.77 @@ -272292,6 +272321,7 @@ 202.164.138.185 202.164.138.187 202.164.138.188 +202.164.138.19 202.164.138.192 202.164.138.195 202.164.138.196 @@ -276891,6 +276921,7 @@ 209.14.30.183 209.14.30.204 209.14.30.205 +209.14.30.209 209.14.30.212 209.14.30.213 209.14.30.216 @@ -276917,6 +276948,7 @@ 209.14.31.190 209.14.31.192 209.14.31.201 +209.14.31.209 209.14.31.215 209.14.31.217 209.14.31.220 @@ -276929,6 +276961,7 @@ 209.14.31.243 209.14.31.244 209.14.31.247 +209.14.31.249 209.14.31.252 209.14.31.253 209.14.31.55 @@ -277497,6 +277530,7 @@ 210.18.189.89 210.18.189.9 210.18.189.90 +210.180.17.140 210.180.237.212 210.182.101.144 210.182.148.126 @@ -290467,6 +290501,7 @@ 220.133.1.130 220.133.103.166 220.133.109.249 +220.133.110.157 220.133.114.189 220.133.115.57 220.133.117.229 @@ -316242,6 +316277,7 @@ 27.210.29.26 27.210.29.83 27.210.3.50 +27.210.32.122 27.210.32.123 27.210.32.125 27.210.32.130 @@ -317685,6 +317721,7 @@ 27.216.116.240 27.216.116.81 27.216.117.178 +27.216.117.54 27.216.118.234 27.216.119.219 27.216.119.228 @@ -346923,6 +346960,7 @@ 36.248.227.203 36.248.228.64 36.248.82.234 +36.248.83.98 36.248.88.35 36.248.92.154 36.248.93.13 @@ -362404,6 +362442,7 @@ 42.226.83.71 42.226.83.78 42.226.83.98 +42.226.85.236 42.226.86.204 42.226.87.123 42.226.88.114 @@ -364695,6 +364734,7 @@ 42.228.39.197 42.228.39.2 42.228.39.204 +42.228.39.211 42.228.39.212 42.228.39.214 42.228.39.215 @@ -372446,6 +372486,7 @@ 42.232.81.147 42.232.81.149 42.232.81.176 +42.232.81.179 42.232.81.181 42.232.81.183 42.232.81.188 @@ -386683,6 +386724,7 @@ 49.117.191.46 49.117.191.78 49.117.191.83 +49.119.187.230 49.119.188.56 49.119.189.124 49.119.189.223 @@ -390365,6 +390407,7 @@ 58.248.142.212 58.248.142.214 58.248.142.223 +58.248.142.227 58.248.142.23 58.248.142.230 58.248.142.236 @@ -391604,6 +391647,7 @@ 58.249.79.16 58.249.79.163 58.249.79.17 +58.249.79.174 58.249.79.175 58.249.79.188 58.249.79.195 @@ -391800,6 +391844,7 @@ 58.249.84.118 58.249.84.124 58.249.84.128 +58.249.84.131 58.249.84.134 58.249.84.148 58.249.84.150 @@ -403297,6 +403342,7 @@ 59.96.37.121 59.96.37.122 59.96.37.123 +59.96.37.124 59.96.37.125 59.96.37.127 59.96.37.128 @@ -407719,6 +407765,7 @@ 59.99.43.187 59.99.43.19 59.99.43.190 +59.99.43.191 59.99.43.192 59.99.43.193 59.99.43.194 @@ -430554,6 +430601,7 @@ 61.53.89.199 61.53.89.2 61.53.89.208 +61.53.89.220 61.53.89.221 61.53.89.227 61.53.89.232 @@ -431632,6 +431680,7 @@ 61.54.69.62 61.54.69.69 61.54.69.70 +61.54.69.77 61.54.69.78 61.54.69.8 61.54.69.95 @@ -445984,7 +446033,6 @@ app.bigplan-alex.com app.boxrcdn.com app.bridgeimpex.org app.calag.at -app.casetabs.com app.catholicchurch.co.in app.choiphui.com app.cloudindustry.net @@ -450216,6 +450264,7 @@ beanmatrix.com beansmedia.com beanssur.com beantreefoods.com +beanx88.xyz beanz-network.com bearcatpumps.com.cn beard-companies.com @@ -456517,7 +456566,6 @@ cdncomfortgroup.website cdndownloadlp.club cdnmultimedia.com cdnpic.mgyun.com -cdnrep.reimageplus.com cdnxh.net cdoconsult.com.br cdolechon.com @@ -457260,7 +457308,6 @@ cheapesthost.com.ng cheapgadgets-gq.000webhostapp.com cheapistan.pk cheapmlbjerseysmarlins.com -cheapmusic.info cheapoakleysunglasses.net cheappigeontraps.com cheapraccoontraps.com @@ -457309,7 +457356,6 @@ cheekie2.neagoeandrei.com cheematransxpressinc.com cheerchile.cl cheerfulgiversneverlack.com -cheerfullydo.com cheesecakery.com.br cheetahridge.mediadevstaging.com chef-solutions.dreamscape.co.in @@ -457748,6 +457794,7 @@ christina.makeyourselfelaborate.com christinablunsum.com christinailoveyousomuchyoumyheart.duckdns.org christinalenway.com +christinekeller.ch christinelebeck.com christinmunsch.com christmasatredeemer.org @@ -463318,6 +463365,7 @@ demo.jjmayurved.com demo.jrkcompany.com demo.kalapifoods.com demo.kanapebudapest.hu +demo.kechuahangdidong.com demo.kzonetechnologies.com demo.lamppostmedia.in demo.lapizblanco.com @@ -465382,7 +465430,6 @@ dl-45538429.onedrives-en-live.com dl-675423.store-downloads.com dl-80076342.md-downloads.com dl-97674424.md-downloads.com -dl-gameplayer.dmm.com dl-link.link dl-link.live dl-link.network @@ -465413,7 +465460,6 @@ dl.repairlabshost.com dl.rina-roleplay.com dl.river-store.com dl.rp-soft.ir -dl.softservers.net dl.svcupdate.com dl.teeqee.com dl.x420.me @@ -466216,8 +466262,10 @@ down.pcclear.com down.post-gg.top down.postch-b.top down.postch-bsw.top +down.postch-de.top down.postch-dfa.top down.postch-dj.top +down.postch-dl.top down.postch-fa.top down.postch-fj.top down.postch-kf.top @@ -468028,7 +468076,6 @@ economiadeltempo.it economiadigital.biz economika.com.ve economizei.shop -economplast.com economywindowcleaner.com econoteen.fea.usp.br econotel.us @@ -472737,7 +472784,6 @@ files.danwin1210.me files.dropmybin.me files.enjin.com files.gathercdn.com -files.hrloo.com files.l-d.tech files.martellexpress.us files.mirai-2viv.vn @@ -474950,6 +474996,7 @@ fuzzymiles.com fv1-2.failiem.lv fv13.failiem.lv fv15.failiem.lv +fv2-2.failiem.lv fv2-7.failiem.lv fv3.failiem.lv fv6.failiem.lv @@ -479193,7 +479240,6 @@ hangtotma.com hangtrentroi.com hangulcafes.ga hanh.cz -hanhtrinhtamlinh.com hanhtrinhthanhnienkhoinghiep.vn haniamarket.com hanict.org.vn @@ -479388,7 +479434,6 @@ harrisburgprinting.com harriscustomcatering.com harrisheatpumps.nz harrisnewtech.ir -harrisoncarter.com harrisonlily.co.uk harryfang.com harryhiggins.com @@ -482189,7 +482234,6 @@ i-sharecloud.com i-supportcharity.com i-vnsweyu.pl i-voda.com -i.fiery.me i.fluffy.cc i.funtourspt.eu i.ooxx.ooo @@ -488570,6 +488614,7 @@ kebunrayabaturraden.id kec-cendana.enrekangkab.go.id kec-wlingi.blitarkab.go.id kecforging.com +kechuahangdidong.com keciorenkoltukyikama.net keckarangdadap.pekalongankab.go.id kecsfila.hu @@ -506373,6 +506418,7 @@ osrsport.com ossandonycia.cl osscaar.com osservatore.betacom.it +ossi4.51cto.com ossianlaw.com osslusturv.com ossoriobouliz.com @@ -509705,6 +509751,7 @@ politinsky.000webhostapp.com politrix.net poliyzsl.host poljimenez.com +polk.k12.ga.us polka32.ru polkapower.com polkolonieb4k.pl @@ -510876,7 +510923,6 @@ professionalshop.in professionalwaiterskollege.org professionelelit.com professorsgallery.com -profetestruec.net profexsystem.com proffessia.ru proffice.com.pl @@ -511254,6 +511300,7 @@ protech.binarybizz.com protech.mn protechcarpetcare.com protechgroup1.com +protect.mimecast-offshore.com protectiadatelor.biz protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org protection.pecol.eu @@ -519360,7 +519407,6 @@ shareallfilesthroughsecureexchangesystem.duckdns.org sharebook.tk sharechautari.com shared-cnd.com -shared.pdffiller.com shareddocuments.ml shareddynamics.com sharedeconomy.eu @@ -524992,6 +525038,7 @@ sup3rc10ud.ga supadom.fr supamidland-my.sharepoint.com supcargo.com +supdate.mediaweb.co.kr super-filtr.ru super-gamezer.com super-industries.co @@ -529610,7 +529657,6 @@ tlcmoto.com tldrbox.top tlextreme.com tlfthelifefactory.com.au -tlgur.com tlkcloudem.com tlktdsfj.sha58.me tlpclient.site @@ -531246,6 +531292,7 @@ tsport88.com tsr-mark.xyz tsredco.telangana.gov.in tsrj.monster +tsrv2.top tst.marineindust.com tstfrigo.com tsugite.youbi.me @@ -532657,6 +532704,7 @@ update-chase.justmoveup.com update-prog.com update-res.100public.com update.5v.pl +update.7h4uk.com update.att.tools update.bracncet.net update.bruss.org.ru @@ -532896,6 +532944,7 @@ url-update.com url-validation-clients.com url.246546.com url.57569.fr.snd52.ch +url2.mailanyone.net url3.mailanyone.net url5459.41southbar.com url675.textilmallorca.com @@ -534294,7 +534343,6 @@ viettrungkhaison.com viettrust-vn.net vietucgroup.org vietup.net -vietvictory.vn vievioparapija.eu view-indonesia.com view-your-website.com @@ -534748,6 +534796,7 @@ visual-sounds.com visualblends.com visualdata.ru visualdimensioniq.com +visualdive.com visualendodontics.net visualgag.co.uk visualhome.cl @@ -535826,7 +535875,6 @@ wc2018.top wc3prince.ru wcare.nl wcbgroup.co.uk -wcdownloadercdn.lavasoft.com wcdr.pbas.es wcf-old.sibcat.info wcfamlaw.com @@ -537492,6 +537540,7 @@ workingin-my.sharepoint.com workingonit.site workingpainters.com workingroofers.com +workingsolutionsrome.org workingwell.club worklinic.com.br workmate-sien.com @@ -539858,7 +539907,6 @@ yoyoplease.com yoyoso.nz yoyoteacher.cn yp.dcyazilim.com -yp.hnggzyjy.cn ypbb.or.id ypddf.org ypicsdy.cf @@ -540807,6 +540855,7 @@ zoovetdv.ru zoox.com.br zoparo.nl zopbxtjiuykhyyp.usa.cc +zopro.duckdns.org zoracle.com zorancreative.com zoratech.ro @@ -540986,6 +541035,7 @@ zzznan.com ||10xspace.com/wp-includes/wucz92vcwvzmvwqubaa/$all ||118travel.net/ds/1512.gif$all ||11woodwork.com/wp-content/themes/betheme/functions/reporting/$all +||123tadi.com/invoice-status/invoice-0321355444-jun-20$all ||150.co.il/anydesk.exe$all ||1drv.ms/u/s!ag4kn4iexyehdrfvrvxtguoxngo$all ||1drv.ms/u/s!agcd_mpjhjpca7ysbeu0vuagxo8?e=hsbfwp$all @@ -541657,6 +541707,7 @@ zzznan.com ||app.box.com/s/4d9mmj01l7lu3a9l9wolep58ceabre6q$all ||app.box.com/s/bowk0dszzo5m272wsclbulh301wiqpjr$all ||app.box.com/s/xqxxhkh7be55cflkzf19toiqy1x6e49h$all +||app.casetabs.com/n/p7nx8575$all ||appengine.google.com/_ah/logout?continue=https%3a%2f%2fswptransaction-scan2034.s3.ca-central-1.amazonaws.com%2fdoc102018.doc$all ||appengine.google.com/_ah/logout?continue=https://swptransaction-scan2034.s3.ca-central-1.amazonaws.com/doc102018.doc$all ||appliancebuddy.in/wp-includes/m7r/$all @@ -543375,6 +543426,7 @@ zzznan.com ||cdn.xiaoduoai.com/cvd/dist/fileupload/1571723382710/9.915787746614242.jpg$all ||cdnrep.reimage.com/prot/protectorpackagerr2023.exe$all ||cdnrep.reimage.com/ver/reimagepackage1874x64b.exe$all +||cdnrep.reimageplus.com/rqt/reimagerepair.exe$all ||cds.d8u8a5x9.hwcdn.net/cat.exe$all ||cds.v2v8s6m2.hwcdn.net/auto/ah_sa.exe$all ||cds.w2w3w6q4.hwcdn.net/auto/ah_sa.exe$all @@ -543388,6 +543440,7 @@ zzznan.com ||charlesedwardltd.com/flipbook/ovxadxjgkq9wxlycpep7g1hbnbtksejh/$all ||charliehospital.com/soc.exe$all ||chattlink.s3.amazonaws.com/msg.exe$all +||cheapmusic.info/cloudnet.exe$all ||cheapnikeairmaxshoes-online.com/0866x/sep/business$all ||cheapnikeairmaxshoes-online.com/0866x/sep/business/$all ||cheapnikeairmaxshoes-online.com/eri8g1mtcmqdynau9plb/swift/200-jahre$all @@ -543396,6 +543449,7 @@ zzznan.com ||cheapwebvn.net/wp-content/cache/inc/$all ||cheapwebvn.net/wp-content/cache/uzlpqwbgic/$all ||checkvisadebitcardbalance.com/fda-approvals-8hh2l/1te6bhsbwbijbe3/$all +||cheerfullydo.com/data/nhtlrr/94046/nbar_94046_29052020.zip$all ||chenqiaorong007.com/wp-content/inh1q4efmt/$all ||chg.org.uk/sites/dokumente/zahlung/zahlungserinnerung-vom-juli/$all ||chiangmainightsafari.com/wp-admin/lrpiggci/$all @@ -543405,8 +543459,6 @@ zzznan.com ||chiptune.com/razor/rzr-winner_intro.zip$all ||chiwextech.com/wp-content/doc/3emfa4346752881571428w8ifsjrcglg8nz0r4mh6/$all ||chonmua.com/wp-content/ptvdkc/$all -||christinekeller.ch/wp-content/uploads/document/840880756/0s7m3d-40676/$all -||christinekeller.ch/wp-content/uploads/eo4iqgqw-nb3k8-4084/$all ||christinewalker.org/wp-admin/xt9snhtexu/$all ||chtr.ch/wp-content/dvf187rvxs9/$all ||cicinc.com.au/iwcqsifh.rar$all @@ -543677,7 +543729,6 @@ zzznan.com ||demicolon.com/dvrguru_revoerror/image/payment$all ||demicolon.com/dvrguru_revoerror/image/payment/$all ||demicolon.com/hers/wp-content/8arij/$all -||demo.kechuahangdidong.com/assets/file/h-585-50-xjfl8wz-oariqb/$all ||demopn.com/lab/components/com_jce/iz9zp-mohfb-cjzg.view/$all ||demopn.com/lab/components/com_jce/mmene-kw_frdpovb-kkj/$all ||demopn.com/lab/components/com_jce/trust.myacc.resourses.biz/$all @@ -543777,6 +543828,8 @@ zzznan.com ||djsrecord.com/wp-includes/abop/$all ||djykybumlu.s3.amazonaws.com/video-6103.exe$all ||djykybumlu.s3.amazonaws.com/video_player.exe$all +||dl-gameplayer.dmm.com/product/apkggame/giga_baldrbringerextendcode/giga_baldrbringerextendcode/win/src/content/data/data/uninstall.exe$all +||dl-gameplayer.dmm.com/product/apkggame/nel_narikiri/nel_narikiri/win/src/content/data/%e3%81%aa%e3%82%8a%e3%81%8d%e3%82%8a%e3%83%90%e3%82%ab%e3%83%83%e3%83%97%e3%83%ab%ef%bc%81.exe$all ||dl-tornj.ir/wp-content/vvevatafqjravmbzpzwy6kzsmbyp2k3zsmhxfwsd/$all ||dl-web.dropbox.com/cd/0/get/bjln5zjy34vnnedqqrxayoz6usv5pbw_rsnjdqfkuuxtizwmo3odzemreetkjmqrut8n_crp55bedhxveeafavwwtt_jvi12lgpk9izpyrzr14dhe0wqtco4qc6dvog4crs/file#$all ||dl.dropbox.com/s/2rkjxc3kbui8rz1/imagen00944272formatopdf%20imagen00944273formatopdf.uue?dl=1$all @@ -544074,6 +544127,7 @@ zzznan.com ||dl.dropboxusercontent.com/s/zetrtbtm7j4elbz/flashplayer_42.38_plugin.js?dl=1$all ||dl.dropboxusercontent.com/s/zhbextywkev7rlm/flashplayer_41.20_plugin.js?dl=1$all ||dl.dropboxusercontent.com/s/zlme2a94peldftk/flashplayer_41.16_plugin.js?dl=1$all +||dl.softservers.net/111000667/optimizerpro.exe%20%20d.tubedimmerapp.com/updater/setup4.exe$all ||dl01.s3.amazonaws.com/offers/2/chrome_search.exe$all ||dl02.s3.amazonaws.com/offers/2/chrome_search.exe$all ||dmaldimed.com/97499dnxqomin/identity/commercial$all @@ -560358,6 +560412,8 @@ zzznan.com ||ec2euc1.boxcloud.com/d/1/a1!1v6vibwx7vlie5y8jj5xm5ipoc9jdxze8ck08lu22jdqvqu0y23hledgazmxqbcukhlgg95jbfv9p6e7n10-td4omxyxferhngbpik8idewoo81utbhmygy4yzt8uxvxi_dnrwzvwtlndrqwk6hotxffg8jkpj8-j3bybrd7yw7n9nyzemoqeelvbjthue6wa3yuozggyesvvg1o6919_nqqhatm_0mampn9-_jtxf4s-ugi1s9il7i1vz-euwgqoqgfey5ojdw8thvvonrqk07jcvnmdwqnxx73l0zvlypuue7zjxsucd5ngxrgnlrokmgqml3gqmvtclnbzspt-4hcnbybe8gfkg2psuvv1aq_omqri7_jbjnodn0k3rmscvbihzzjag_jacj95hxys2nqu5-avfi3mcsbykrgcfcd0f0ubmxy8_u-adp_am2uyu7wjbtlhrmdeya-wvab9_d_rsbzn6qhbobnfb-ijabnqe8ynoztvmmj5-48vxc-gimyw84qv5vvoewlfuazz6lhawnqlsehdoko20t5tsgdq-ixnr9upyrvqgkqg9hpkx37rcfrizch7msfmqqhgbz-2kepa7cuisq2u8z21psh44kaslvzjjckzbjxaazonnqpicscjypbbx8vqrtok7qhix5gnjmofxjghi8dnzcdrvrzwwf9qowdqzmqle38iykwpk_43qarzcyv53ecglsevfziyq5bqgscnvlv9ypi3dlnhklmijhb_-nal1ma_y7hazsqeqks-c-_2pporvy4fabaa7ppnt7cji5vsu1jcfdqk3xg_voorzho8qzmelylrsddbg1k4rbzk7hhqwn_sbr0owykfhvovjqzq1lssanl7n3sjbh_adgrgglq2ojvyqsklvlnet4-3dr8qnksaaphkhmfzaggxffhkiuks7n6dth09683x8t1ape47jo8a3du24wyvolahwxr0i91czhb9fphq2_qbhc66ww4pynr2kvclrajdii50jao1znpe0nbdtqdqc9c4dladdwtrfnh-1lywnfvm1szr-fky7qtf9ysdut3htypftcw-zwftt5yxvxpff6-xxcd599rg8fr2-inwced5f8d3vc_lu3sy9p_-mfnsp_urjy0f9rcy3lnsgb_$all ||ecoachings.in/old/p4hyzkfvgyg3ttigdtdrtzea94vatgnxm/$all ||ecodetect.com.br/wp-admin/burtjklsc/$all +||economplast.com/lypumytb/d4/ce/a64bze4c.zip$all +||economplast.com/lypumytb/ma/25/tt18os7d.zip$all ||edmedicationguide.com/wp-admin/balance/c72682830684102z3frfjy8i55xmv7/$all ||ehitusest.eu/marketplacel/http://oww3quopm9m95oo/ytpjiimeb24c1tpluq/$all ||ehitusest.eu/marketplacel/http:/oww3quopm9m95oo/ytpjiimeb24c1tpluq/$all @@ -560606,6 +560662,9 @@ zzznan.com ||files.fm/pa/good-doctor/rut-view.zip/rut-view.zip$all ||files.gamebanana.com/tools/enchanced_server_picker.exe$all ||files.gamebanana.com/tools/tagconverter.exe$all +||files.hrloo.com/bbs/data/attachment/forum/201212/20/10301044ex3m3s62emr1r7.doc$all +||files.hrloo.com/bbs/data/attachment/forum/201212/20/10301044ex3m3s62emr1r7.doc?n=w+eyvuwtgv3lkzjlt6xln7norq3nrqhnkiblilbluqyuzg9j$all +||files.hrloo.com/bbs/data/attachment/forum/201212/20/10301044ex3m3s62emr1r7.doc?n=weyvuwtgv3lkzjlt6xln7norq3nrqhnkiblilbluqyuzg9j$all ||files.jivosite.com/file-transfer/1621967/2021-03-16/55ec600e4e6500e080c5.doc$all ||files.lashawnbarber.com/$all ||files.lashawnbarber.com/elb.exe$all @@ -560754,8 +560813,6 @@ zzznan.com ||fullsizechevy.com/ups.com/webtracking/wnr-61311531662/$all ||futurereturn.in/wp-admin/personal-section/test-portal/ch0vusjb-ppi3w0ho38i/$all ||fv2-1.failiem.lv/down.php?cf&i=hyg2rxaa&n=new_payment.doc&download_checksum=afa67b9a5998eca281cda22f5585e9dcf764128a&download_timestamp=1547330846$all -||fv2-2.failiem.lv/down.php?cf&i=my59dhhv&n=2562.xls$all -||fv2-2.failiem.lv/down.php?cf&i=redm59qf&n=dfg-016.xls$all ||g.top4top.io/p_1466oo4nj1.jpg$all ||g.top4top.io/p_1697idvgm1.jpg/,/%25temp%25//svchost.exe$all ||g.top4top.io/p_1697idvgm1.jpg/,/%25temp%25/svchost.exe$all @@ -561022,6 +561079,7 @@ zzznan.com ||hampsteadclinic.co.uk/cust-704117-97648/$all ||hana-lebensmittel.de/public_html/qcel2jpgy3ani4rfgymwqqohx8gzqd8q8ycnhec6vwym0he211vhyfnohassxyc68cuuj/$all ||hangarlastik.com/cgi-bin/ui4n/$all +||hanhtrinhtamlinh.com/gpk/personal-section/verifiable-space/d3d-660ut9x793v61/$all ||hanoiemyeuanh.com/f5-irule-qxyqu/rovfsdq9rw1qanbdowrszzaefyzdhm97y0yggabb3lb8p/$all ||hansoliot.com/elderly/static/t1tmaacsquxyhqhjdd5ml7cxdtjqvmpp4d9ixdxwr2/$all ||hanvifa.com/wp-admin/8l/$all @@ -561030,6 +561088,8 @@ zzznan.com ||harmonimedia.com/wp-content/uploads/7pddmqgzsbqh7oub5qdvx2zaeiih22cb3b8anyizwoq2pt/$all ||harmonimedia.com/wp-content/uploads/zol/$all ||harmonimedia.com/wp-content/uploads/zuonvq95yjqednraebjdzemekozxzqeyuq/$all +||harrisoncarter.com/3578001584444_ycu75_resource/kkc/$all +||harrisoncarter.com/3578001584444_ycu75_resource/yzgvvr/$all ||hastebin.com/raw/agabavacew$all ||hastebin.com/raw/aleyumocin$all ||hastebin.com/raw/azuhivedeh$all @@ -561147,6 +561207,7 @@ zzznan.com ||i.cubeupload.com/euev6n.jpg$all ||i.cubeupload.com/ez3vpt.jpg$all ||i.cubeupload.com/gmetap.jpg$all +||i.fiery.me/5vdk.png$all ||i.imgur.com/3zblzb6.png$all ||i.imgur.com/6q5qhhd.png$all ||i.imgur.com/6wijvdz.png$all @@ -561387,8 +561448,6 @@ zzznan.com ||kbpassociates.in/about-me/paclm/c3rsb8vy1dlb/$all ||kd.nuftp.com/pulkit/attachments/$all ||kd.nuftp.com/pulkit/etrac/l1vyfdl/$all -||kechuahangdidong.com/wp-admin/esp/0ebq5jmrn3i6/6qh4jn-346396224-48-1pa3isys-ble49fo32t5/$all -||kechuahangdidong.com/wp-admin/mncrbbx/6xpzk58cu/4-4637795257-79951-vdhdt1n26o-r0w7n/$all ||keerimeeri.com/cgi-bin/parts_service/$all ||kemahasiswaan.um.ac.id/wp-content/uploads/544xiwaqeoz/payment/smallbusiness$all ||kemahasiswaan.um.ac.id/wp-content/uploads/544xiwaqeoz/payment/smallbusiness/$all @@ -564801,23 +564860,6 @@ zzznan.com ||oshiscafe.com/wp-admin/5dm/$all ||osliving.com/vyop-n8taxexfiqihcz_tqpsraxby-hk$all ||osliving.com/vyop-n8taxexfiqihcz_tqpsraxby-hk/$all -||ossi4.51cto.com/attachment/201203/4594712_1333015433.rar$all -||ossi4.51cto.com/attachment/201204/4594712_1334794324.rar$all -||ossi4.51cto.com/attachment/201204/4594712_1335670976.rar$all -||ossi4.51cto.com/attachment/201205/4594712_1336127240.rar$all -||ossi4.51cto.com/attachment/201205/4594712_1337420961.rar$all -||ossi4.51cto.com/attachment/201205/4594712_1337853814.rar$all -||ossi4.51cto.com/attachment/201205/4594712_1337902068.rar$all -||ossi4.51cto.com/attachment/201205/4594712_1338219299.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1338596584.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1338631130.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1338940618.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1339042034.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1339151181.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1339214458.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1339410537.rar$all -||ossi4.51cto.com/attachment/201206/4594712_1339456815.rar$all -||ossi4.51cto.com/attachment/201206/5305206_1339979954.rar$all ||overwatchboostpro.com/e46a70d24f4162901a5dfbc139b40d49/gxgck/$all ||overwatchboostpro.com/e46a70d24f4162901a5dfbc139b40d49/lm/37-2371894-54-3l6f-2cmce/$all ||overwatchboostpro.com/ynibgkd65jf/sites/2bmfkc0j7qe8_58yyhd4-3344823406/$all @@ -570951,7 +570993,6 @@ zzznan.com ||pmjnews.com/wp-content/pdc88/$all ||podcastforprofit.tv/wp-admin/private_section/guarded_forum/bnlc9f46p_uu72sywu07ww/$all ||podisticaavisderuta.it/flags/client.rar$all -||polk.k12.ga.us/userfiles/13/classes/2473/8thpssyllabus.doc$all ||polyproductions.com.au/in-what-jgcak/c5njrzmm4sqrvaes3grdnn2ccj7nzt/$all ||porlacalledelmedio.com/device-unlock-xlzl9/uqaqjbsmpt2loeq5sj45vwski7aguudkiasnuu09gwg8jyhmx3alyemphhpm/$all ||pornhub.com/x/xff.exe$all @@ -570980,6 +571021,8 @@ zzznan.com ||procrossover.ru/wp-content/uploads/2020/10/skodaqq.jpg$all ||prodijital.com.tr/wp-admin/trust.accs.send.com/$all ||products.office.com/en-us/cmsimages/office365logo_orange.png?version=b8d100a9-0a8b-8e6a-88e1-ef488fee0470/$all +||profetestruec.net:8000/in3.ps1$all +||profetestruec.net:8000/in6.ps1$all ||progressimos.com/administrator/paclm/shewunrxfqofa7l0r1bqpsv_jt9umsge-64903301/$all ||promotedigitally.net/wp-includes/8m/$all ||pronomina.store/wp-admin/bb48974/$all @@ -570993,9 +571036,6 @@ zzznan.com ||protect-us.mimecast.com/s/7ihcc82oqycqx96qh15qw5$all ||protect-us.mimecast.com/s/c27ac0rx9ru80p3fw0bgj$all ||protect-us.mimecast.com/s/qki9c73wxjupxq5ps8qcm_$all -||protect.mimecast-offshore.com/s/ip17cn9blzfnq4n4h4tudd?domain=meraqsa.com/$all -||protect.mimecast-offshore.com/s/loqwcg5rvpcjndxqc76apn?domain=ronakfence.ir/$all -||protect.mimecast-offshore.com/s/rd0zcjqxyvf8w6o3igppxq?domain=ronakfence.ir/$all ||protect2.fireeye.com/v1/url?k=59eacb3c-0560e9d5-59ed97de-0cc47ad93e2e-0f5e34e79adab692&q=1&e=e7991bbc-cc93-4814-a8f2-fd6d6950b0d5&u=https%3a%2f%2fwww.mediafire.com%2ffile%2fs2uyxs8t8kbuyye%2fdocumentos_de_env%25cdo.7z%2ffile$all ||protect2.fireeye.com/v1/url?k=6d0c09d2-33bdd2b2-6d0f7943-86e2237f51fb-ab55eb53c2dfee1f&q=1&e=358c9b57-d351-4b0f-80cf-d0755ec21127&u=https://pottershousedurban.co.za/cgi-bin/file/xzbx0cb5wywuw5/179vj6b9dpsp7advozp/$all ||prowestappraisal.com/ms-t/xqgkotgvdwhezypdfhwvwrjfe/$all @@ -571608,6 +571648,7 @@ zzznan.com ||shared.outlook.inky.com/link?domain=www.toziba.ir&t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdunfugkaq_jd7tqby28qtte2siucq4akhiquccnh36heusom_93hq0odndjazm7p7jrqbtgtkoxmvihjsn4atsxnae0sfiliaq_yjwemmigieajwaghr4flxxomyqraaocn-olxohlupdgzsxe7prokpvd5qbqawg1wcoobwjkz3ufhzxrsqdhoeov97zesjd3ud42czjzno6tbykppb0q2sllrejuqukofjgvoh2meqyo3nmwrvhrrxjjy_wjowcvdf-eyutqxtbpcsvrxzwosy4xzirljn8gab75zz7x9l-wuzbwemg7on1all8m9bux-5uz2yu_7siifpeuvfexnqvcu5-4aze-6xfvs5svlghmixjb1iockmarmeqzkscgzgr_7818pqjn19jvyhz.meyciqdjb9hlkixl4sz_rt8-tj8v7t6tzcbxfjgcuyhbc8ixuwihapwstswmgpu_k43h-va03ffjltif7n-k3qrucylug8il/$all ||shared.outlook.inky.com/link?domain=www.toziba.ir/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxduf1vgjau_s99dqa4t-mtbcbortbrpqqhireoqmmllilisv--8rrkj-fm3pp1jrqbxuzogu6lajgr-gscydidneklueqkyghxataqeskap0d1icdpx5-xhepmyfztb4u_1er9gwqlls0inmoz6zpd1y8ybaougl6eioelie1pd1fvuhzk2mfxau_wb173mbp_9kvnloytl6c1ida15m5hc9eynkkqkaruwsinajexjjmyy87akjxrhm55fe5yxhmndvmrtoiww3ewve8cwlmrcpelfi7smoghdistd2_pyu4jwk0iz-ncvdrjbzn2vt13vv4de76-4cqhacp8i-kpt7tl7cfos3vxc_otje5d44bihawljjdnkjsnzktprjwzkcv_2xpzzdhpl9e5g6k.meucigd6xwariut2lkiettiajcosxyluv7ub6nhbepewswmwaiea4mzpunjaca7lslweyqnda4gpvqjwhufuenzur1jmp64//$all ||shared.outlook.inky.com/link?domain=www.toziba.ir/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdunfugkaq_jd7tqby28qtte2siucq4akhiquccnh36heusom_93hq0odndjazm7p7jrqbtgtkoxmvihjsn4atsxnae0sfiliaq_yjwemmigieajwaghr4flxxomyqraaocn-olxohlupdgzsxe7prokpvd5qbqawg1wcoobwjkz3ufhzxrsqdhoeov97zesjd3ud42czjzno6tbykppb0q2sllrejuqukofjgvoh2meqyo3nmwrvhrrxjjy_wjowcvdf-eyutqxtbpcsvrxzwosy4xzirljn8gab75zz7x9l-wuzbwemg7on1all8m9bux-5uz2yu_7siifpeuvfexnqvcu5-4aze-6xfvs5svlghmixjb1iockmarmeqzkscgzgr_7818pqjn19jvyhz.meyciqdjb9hlkixl4sz_rt8-tj8v7t6tzcbxfjgcuyhbc8ixuwihapwstswmgpu_k43h-va03ffjltif7n-k3qrucylug8il//$all +||shared.pdffiller.com/1395f7beaf30f1943ac9e1b9800a8fbf/8c7dd922ad47494fc02c388e12c00eac/cdecfead5bd78cb1c29f931bc49ad2db.exe?t=1549302986$all ||shatki.info/templates/ld_benew/images/blue/messg.jpg$all ||shellter-static.s3.amazonaws.com/media/files/5adbc741-fe58-4372-ad03-f27df73dbf1c.exe$all ||shengen.ru/sites/default/files/de/rqtpjz3882750/gescanntes-dokument/rechnungsanschrift/$all @@ -573414,7 +573455,6 @@ zzznan.com ||sulselekspres.com/test777/a/$all ||sunchipaint.com.vn/wp-admin/document/dawb84xl_piuu2as-9919296896/$all ||suncitycarrental.com/ingersoll-rand-7qtka/8jhka7zy/$all -||supdate.mediaweb.co.kr/download/pica/client/data/uninstall_1.exe$all ||super-registry.s3.eu-central-1.amazonaws.com/installc_sh_directly.exe$all ||superbeaute.ca/wp-content/nachrichten/nachprufung/de_de/04-2019/$all ||superdomain1709.info/c4fxp3oiuoyf.67w$all @@ -573588,6 +573628,7 @@ zzznan.com ||tldrnet.top/spm/3$all ||tldrnet.top/t.exe$all ||tldrnet.top/winsysdrv.exe$all +||tlgur.com/d/8lop0bv4/$all ||tlsac.pe/wp-touch.php$all ||tmpfiles.org/dl/160986/0702.exe$all ||tnkhanh.info/wp-admin/az0fysfnexo1qfw9si6bvfxs/$all @@ -573672,7 +573713,6 @@ zzznan.com ||ts-prod-assets.tripleseat.com.s3.amazonaws.com/assets/009/486/201/thevillagepub.doc?1545223316$all ||ts-prod-assets.tripleseat.com.s3.amazonaws.com/assets/010/943/655/inv11533395908.doc?1553863076/$all ||tsg339.com/invoice/$all -||tsrv2.top/telikkk.exe$all ||tsrv4.ws/23.exe$all ||tsuburaya-prod.co.jp/wp-content/plugins/wp-ogp/sa.exe$all ||ttdvl.s3.ca-central-1.amazonaws.com/val9fx4kx57wgrb.jpg$all @@ -574348,9 +574388,6 @@ zzznan.com ||up4net.com/uploads/up4net-rufus-3-9p.exe$all ||up4net.com/uploads/up4net-stories.exe$all ||upafrique.com/cgi-bin/ifmg/$all -||update.7h4uk.com:443/antitrojan.ps1$all -||update.7h4uk.com:443/cohernece.txt$all -||update.7h4uk.com:443/logos.png$all ||update.drp.su/mustang/tools/run.hta$all ||update.drp.su/nano/$all ||update.drp.su/nps/offline/bin/tools/run.hta$all @@ -574402,7 +574439,6 @@ zzznan.com ||url.emailprotection.link/?bgmvicpuho15c9_q9hiofgnmkaco0q_lujjcaeowkfik_hdtt1uqmbkpovhxykckgjoqoytv_u0g2umkhd4mbi9ms8vo3vliq2clouuaa6no2a7ij5ljfsouoeememvmi/$all ||url.emailprotection.link/?bizyxbw1fdagsfcc1n6ep1awpdx9dr0brnjjqwgyaofpw98limviipvrszjnzzluclpeqqdywfxwnwudvwrljcufuhl2_nha0bs8wz9jmbahcciikbseljewayzbe_cnd/$all ||url.sg/rwtho$all -||url2.mailanyone.net/v1/?m=1hibcm-0003zv-63&i=57e1b682&c=sb1blj46bk32u6f729r5t_slvkx-heewxh20_zdn9-3ktcc0-kn35fykilpydgeyvrbwqwb5h__fk383wtdakqftjlelxz06jbaglri5jmujnydjkasqxwdtg2hn-_be1dzrnthvvhigyhm_tvbew342habp8dtit9jjlieuc2x-ipgdgipe7y_c9jhe69532gmnxozb5wifjfbstzicagmtpg6yxmreaf0sq2dgo-ksy54hetfhn6gwm4kiw2vvcqx17a9bm6ykn8bwpwdjwg/$all ||urldefense.com/v3/__http:/download.tikishop.top/temp/oct/zxpz9h87ye/__;!!fbndfrmfwymjic8!esuixa6kh9x3c2evnf06q3vphe7ce6thjgjxuygtgkahdoypzovx_isni9xonn9idgfjjqtcun8$/$all ||urldefense.com/v3/__https://www.geoffoliver.org/simple-blog.off/vendor/payment/9yiv2xys/__;!!okyw9je!2zzbjlkqkjmstcwtza6cy_dauiy-njmys3cs6uteawgyow8yhyesg5jhjtttdwaxadrnh5k$/$all ||urldefense.com/v3/__https:/www.geoffoliver.org/simple-blog.off/vendor/payment/9yiv2xys/__;!!okyw9je!2zzbjlkqkjmstcwtza6cy_dauiy-njmys3cs6uteawgyow8yhyesg5jhjtttdwaxadrnh5k$/$all @@ -574470,13 +574506,12 @@ zzznan.com ||videract.com/pnllsek25ksj/fnw81309/$all ||vietnhabienhoa.com/wordpress/quty/$all ||viettinlaw.com/xmtuzix/docs/k9zuyya91v/$all +||vietvictory.vn/wp-content/themes/eikra-child/languages/1c.jpg$all ||vinylgemsmusic.com/backup/204316369204/hqrzlbgp0barc0asoy/$all ||viportal.co/shoock/file/$all ||viraltoday.eu/h/l4nv04gfxkenjl79pfwjluj3b4sz2rteac8wsayji0ojxndugigdp39ou5ovjrikih/$all ||virtualsalud.com/ice-table-ui4is/cywvx6te2xnomekqozqpqzug8gl9wdwgfhs1mec2/$all ||visionis.cl/wp-content/xokxbvebnljtkbdw0uzpcyzx7q90itzxhjbfurgayuzizl4cvfmpqdtduc/$all -||visualdive.com/wp-admin/balance/4343726113/u2r5u-00497429/$all -||visualdive.com/wp-content/k8kibhjxoc03akqd0hampdubw8dg8zgiuo3pcqu6lbns5b5yrs4ky/$all ||vitoptaxi.com/wordpress/hujpfm0uku30m2ykivdadaxqzsfz/$all ||vivc.edu.vn/projectile-motion-ppunf/hfbe4zfur2uhbemlwcorvuzmld6khy13xcsvttcja2ss/$all ||vivc.edu.vn/projectile-motion-ppunf/nymv4kwbybjiocron9ml1idbsarccn/$all @@ -574516,6 +574551,7 @@ zzznan.com ||watchesprime.com/mohsen/plane/gsbkhhjz/$all ||watchnshirt.com/y/l7z9yca/$all ||wayfarersb.com/wp-content/3ug9xuf6afea8g0w8notuh7hqfjbnuslbquftemauf/$all +||wcdownloadercdn.lavasoft.com/4.3.1908.3686/wcinstaller.exe$all ||wcmpdemos.com/all-in-one-demo/320488936_ghdygubfhgx_disk/security_3364051_onnamfnt7/hzsqxrzyn6bl_3twv69/$all ||wcpaherrin.net/q/jg/$all ||web-de-login.de/wp-admin/hrgys0hxxkmd1fsjsggdpbjl1nwh2ucsanhjmtrovh82it0jti1diidnl5pwljdxq/$all @@ -574674,6 +574710,7 @@ zzznan.com ||youmeet.ir/wp-content/uploads/ch/common-disk/special-warehouse/617ev-krzevvj4biu/$all ||yourtrending.com/wp-content/yesa161/$all ||youthref.org/content/cninqkopm0/$all +||yp.hnggzyjy.cn/common/yz.vbs$all ||yq001.com/admin/docs/$all ||ytrytx17x.s3.us-east-2.amazonaws.com/p-17-4.dll$all ||yunwu.sx/wp-admin/meggkxntjj8h/$all @@ -574710,8 +574747,6 @@ zzznan.com ||zoom.lk/tv/touch/app/service.exe$all ||zoomdrive.com.au/ndoaik/nqad_06371857_01062020.zip$all ||zoomdrive.com.au/ndoaik/nqad_926594_01062020.zip$all -||zopro.duckdns.org/cbsmsg.zip$all -||zopro.duckdns.org/cbsmsg1.zip$all ||zorem.com/wp-content/public_segment/sec/eng/accs/open_resourse/$all ||zrfghcnakf.s3.amazonaws.com/video.exe$all ||zrfghcnakf.s3.amazonaws.com/video_play.exe$all